Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

StackOverflow Tweaks Tool

dfignoicphdepgloiodeaiokaepjbnan
Risk Score
4.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 89
Rating 5.0
Last updated 2024-08-03 (22 months ago)
Manifest version MV3
CSP present ❌ no
Developer fasanriccardo21@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • Brand impersonation: 'stackoverflow' in name; developer is unverified gmail user with no business domain.
  • Extension is 22 months stale (no update since Aug 2024); maintenance risk rising.
  • Developer uses free webmail (gmail) with no verified business identity or publisher badge.
  • No CSP present (MV3 mitigates somewhat but adds mild network risk surface).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; 'stackoverflow' in title; developer domain is gmail.com, not stackoverflow.com.
  • privacy_policy_generic store Policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • free_webmail_developer store Developer email fasanriccardo21@gmail.com; no verified publisher badge; no business domain.
  • maintenance_stale store months_since_update=22; falls in 12-24mo band → +6.0 maintenance pillar.
  • no_csp manifest content_security_policy=null; MV3 so no v2 +2.0 penalty, but inherently no declared CSP.
  • narrow_host_scope manifest content_scripts limited to *://*.stackoverflow.com/questions/*/*; no broad host permissions declared.
  • is_featured_by_google store is_featured_by_google=true; provides -2.0 reputation discount capped per featured badge.
  • no_bad_hosts_or_cves crx cve_findings_raw=[], bad_host_hits=[], code_findings_raw=[]; no malicious signals detected.

Permissions Breakdown

  • storage low Stores user preferences locally; no cross-origin data access.
  • content_scripts *://*.stackoverflow.com/questions/*/* low Narrowly scoped to stackoverflow question pages only; low blast radius.

Pillar Scores

Permissions0.50
Reputation7.00
Network0.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA 49ef7fb7b5c8…
Force block — not fired
Score recovered no
Elapsed 19.0s