Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Best AdBlocker

dllpkaoladhieehkbjbifonfblhgkoki
Risk Score
3.62
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Adblock
Installs 100,000
Rating 4.4
Last updated 2026-03-08 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer bestadblocker@outlook.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail developer (outlook.com) with no developer name: unverifiable identity behind a 100K-install adblock extension.
  • Uninstall URL hijack and install URL hijack both enabled: classic traffic-monetization/surveillance shell pattern.
  • External JS host (titanpopupblocker.com) loaded from a third-party domain with no threat-intel clearance; supply-chain risk.
  • webRequest + scripting + <all_urls>: extension can observe and modify every request and page across all sites.
  • No developer name on listing combined with free webmail increases accountability gap significantly.

Evidence

  • install_url_hijack + uninstall_url_hijack both true crx onInstalled and setUninstallURL both configured; classic monetization/tracking shell pattern. +3.0+2.0 Webstore.
  • developer_email is free webmail, no developer_name store bestadblocker@outlook.com with empty developer_name; Reputation +1.5+1.0.
  • js_external_hosts: titanpopupblocker.com crx External JS loaded from titanpopupblocker.com; not in bad_host_hits but is a third-party domain outside dev control.
  • webRequest + <all_urls> manifest webRequest observes all network traffic across every visited site; high surveillance surface.
  • verified_publisher: true store Verified publisher badge present; applies -3.0 to Reputation but capped due to free-webmail floor.
  • privacy_policy_classification: fully scoped, all fields true api Policy declares collection, retention, third-party sharing scoped to extension. Privacy pillar = 0.0.
  • cve_findings_raw empty, code_findings_raw empty, obfuscation_score 0.0 crx No CVEs, no suspicious code patterns, no obfuscation detected in 14 JS files.
  • months_since_update = 5 store Updated 3-6 months ago; Maintenance +1.5.

Permissions Breakdown

  • storage low Stores extension settings locally.
  • unlimitedStorage low Extended local storage for filter lists; expected for adblocker.
  • declarativeNetRequest medium Core blocking mechanism; appropriate for adblock category.
  • scripting high Can inject JS into any page when paired with <all_urls>.
  • alarms low Periodic background tasks; low intrinsic risk.
  • activeTab low Temporary access to current tab only.
  • tabs medium Reads tab URLs and metadata across sessions.
  • webRequest high Observes all network requests across all URLs; high surveillance capability.
  • <all_urls> (host) high Grants access to every site visited; amplifies scripting and webRequest risk.

Pillar Scores

Permissions5.50
Reputation6.50
Network4.00
Webstore6.50
Maintenance1.50
Privacy0.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:50
Listing SHA 9241cdcbeffe…
Force block — not fired
Score recovered no
Elapsed