Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Unfollower & Follower Tracker for IG

dcmoiapnniffbbfhdkmnkbfcmkehncai
Risk Score
5.29
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 1,000
Rating 5.0
Last updated 2026-01-02 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer exportmyinfohq@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail gmail dev with no verified publisher; privacy policy hosted on ext-boost.com, not developer's own domain.
  • Content scripts declared for <all_urls> but function only requires instagram.com — massive scope mismatch.
  • Broad host_permission https://*/* grants access to all HTTPS sites, not just Instagram.
  • Privacy policy discloses data collection AND third-party sharing but lacks retention policy; third-party domain (ext-boost.com) raises concerns.
  • No CSP + DOM innerHTML sink in popup JS increases XSS risk if variable is user-controlled.

Evidence

  • free_webmail_developer store Developer email exportmyinfohq@gmail.com is free webmail; no verified publisher badge.
  • broad_host_permissions manifest host_permissions include https://*/* — all HTTPS sites, far beyond Instagram.
  • content_scripts_all_urls manifest content_scripts_matches includes <all_urls> alongside instagram.com — scope mismatch.
  • privacy_policy_third_party_sharing api Policy at ext-boost.com admits data_collection=true, third_party_sharing=true, retention=false.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
  • dom_xss_sink crx innerHTML assignment from variable in popup.100f6462.js; DOM-XSS risk without CSP.
  • external_host_api.ext-api.com crx JS contacts api.ext-api.com — third-party API domain tied to ext-boost.com operator.
  • identity_email_permission manifest identity.email permission allows harvesting user Google account email address.

Permissions Breakdown

  • storage low Local data persistence; standard low-risk permission.
  • identity medium Access to Chrome identity; can retrieve user OAuth tokens.
  • identity.email medium Explicitly retrieves user email address via Chrome identity API.
  • tabs medium Can read tab URLs and titles; broad page visibility.
  • https://*/* high Broad host access across all HTTPS sites; enables content injection anywhere.
  • *://*.instagram.com/* high Full access to Instagram sessions, including cookies and page content.
  • https://*.cdninstagram.com/* medium Access to Instagram CDN assets; less sensitive but broadens surface.
  • https://*.fbcdn.net/* medium Access to Facebook CDN; tied to Instagram session data.
  • <all_urls> (content_scripts) high Content scripts injected on all URLs — far beyond Instagram scope.

Pillar Scores

Permissions7.50
Reputation7.50
Network4.50
Webstore3.50
Maintenance3.50
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:11
Listing SHA 6eeb8e82ee3c…
Force block — not fired
Score recovered no
Elapsed