Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Type-ahead-find

cpecbmjeidppdiampimghndkikcmoadk
Risk Score
4.14
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Accessibility
Installs 8,000
Rating 4.5
Last updated 2025-03-28 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer typeaheadfind@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Content scripts injected on all URLs (http, https, file, ftp) with no CSP — broad page-content access.
  • Privacy policy is generic Google account policy; scope_extension=false, admits data collection and third-party sharing — not scoped to this extension.
  • Developer uses free Gmail account with no verifiable business identity or domain.
  • Extension last updated 15 months ago; not abandoned but trending stale with broad host injection surface.
  • No CSP declared (MV3 default mitigates somewhat, but js_external_hosts reference code.google.com and www.gnu.org).

Evidence

  • broad_content_script_injection manifest content_scripts_matches covers http://*/* https://*/* file://*/* ftp://*/* — all pages on all protocols.
  • generic_privacy_policy store Privacy policy points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email typeaheadfind@gmail.com; no verifiable business domain or website.
  • no_csp manifest csp_present=false; MV3 default applies but no explicit extension CSP declared.
  • external_js_hosts crx js_external_hosts: code.google.com, www.gnu.org — referenced but no code_findings flagged.
  • stale_update store Last updated March 28 2025; 15 months since update — approaching high-risk staleness band.
  • no_bad_hosts_no_cves api cve_findings_raw empty; bad_host_hits empty; monetization_hits empty; code_findings_raw empty.
  • operator_cluster_clean api sibling_count=0; no related suspicious extensions under same fingerprint.

Permissions Breakdown

  • storage low Used to persist user settings; low capability, no data exfil risk alone.
  • content_scripts: http://*/* https://*/* file://*/* ftp://*/* high Broad host injection on all URLs; can read/modify any page content.

Pillar Scores

Permissions2.00
Reputation6.50
Network0.00
Webstore0.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA 02c614e0b6b4…
Force block — not fired
Score recovered no
Elapsed 19.4s