Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

BetterPlayer - A Modern Video Player

dbcfpoaehlbfdeeaonihhkoocmjgalco
Risk Score
5.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 1,000
Rating 4.0
Last updated 2024-03-29 (27 months ago)
Manifest version MV3
CSP present ❌ no
Developer nmihaly0113@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • content_scripts on <all_urls> gives read/write access to every page visited despite no declared permissions.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection & 3rd-party sharing.
  • Extension not updated in 27 months; abandoned or unmaintained, raising supply-chain risk.
  • Developer uses free Gmail address with no verifiable business identity.
  • No CSP declared; MV3 default mitigates eval but leaves extension with no explicit policy.

Evidence

  • content_scripts_all_urls manifest content_scripts_matches=["<all_urls>"] with empty permissions[] — broad reach via content injection on all sites.
  • generic_privacy_policy store Privacy policy points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • maintenance_stale store Last updated March 2024, 27 months ago — deep into stale band (+8.5).
  • free_webmail_developer store Developer email nmihaly0113@gmail.com; no associated business domain; free-webmail fingerprint.
  • featured_by_google store is_featured_by_google=true; provides partial reputation discount but does not override privacy/staleness concerns.
  • no_csp manifest content_security_policy=null; MV3 prevents remote code loading by default, limiting but not eliminating risk.
  • no_bad_hosts_or_cves crx cve_findings_raw=[], bad_host_hits=[], code_findings_raw=[] — no active malicious signals detected.
  • js_external_host_github crx js_external_hosts=["github.com"]; single trusted host, low network risk.

Permissions Breakdown

  • content_scripts:<all_urls> high Content script injected on every URL; can read/modify any page DOM.

Pillar Scores

Permissions4.00
Reputation7.00
Network0.00
Webstore2.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA 6e69f359a2f0…
Force block — not fired
Score recovered no
Elapsed 19.2s