Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

in5 Animated GIF Maker

dldadkjlkldanpbaicclkikgkgpgpflj
Risk Score
5.46
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 1,000
Rating 2.2
Last updated 2023-03-28 (39 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@ajarproductions.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Extension is 39 months stale (>36mo maintenance band) — abandoned, unpatched attack surface.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • tabCapture + content_scripts on <all_urls>: can record any tab; broad injection across all sites.
  • DOM-XSS sink (innerHTML with user-controlled variable) in lib/helpers.js.
  • No developer name listed; low rating (2.2); low install base limits blast radius but raises quality concerns.

Evidence

  • maintenance_stale store Last updated March 2023; 39 months since update — zombie tier (+10.0 maintenance).
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • content_scripts_all_urls manifest content_scripts matches <all_urls> — injected into every page the user visits.
  • tab_capture_permission manifest tabCapture grants ability to stream capture any active tab; high capability for a GIF tool.
  • dom_xss_sink crx lib/helpers.js: innerHTML assigned from variable str — DOM-XSS risk; csp_present=true so +0.5 only.
  • reputation_no_dev_name store developer_name is empty; no 'Offered by' name visible; not verified publisher.
  • low_rating store Rating 2.2 (below 3.0 threshold) though rating_count not confirmed >=50.
  • cve_findings_empty crx No CVEs detected in bundled JS libraries; CVE pillar = 0.0.

Permissions Breakdown

  • tabs medium Can enumerate open tabs and their URLs; moderate privacy surface.
  • activeTab medium Grants transient access to the current tab's content on user action.
  • tabCapture high Can capture audio/video stream of the active tab — core GIF-making function but high capability.
  • storage low Local extension storage only; no cross-origin data sharing implied.
  • content_scripts <all_urls> high Content script injected into every page; combined with tabCapture raises broad capture surface.

Pillar Scores

Permissions3.30
Reputation6.00
Network0.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA ad4289bcc6ba…
Force block — not fired
Score recovered no
Elapsed 25.2s