Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dark Mode

dmghijelimhndkbmpgbldicpogfkceaj
Risk Score
4.85
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Accessibility
Installs 2,000,000
Rating 3.6
Last updated 2026-07-28 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer grephyr.prj@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension at all, collecting and sharing user data admitted.
  • Gmail developer with no business domain; unverifiable identity behind 2M-install extension with <all_urls>.
  • install_url_hijack and uninstall_url_hijack flags set; onInstalled/setUninstallURL to undisclosed third-party URL.
  • 8 external JS hosts referenced (github, youtube, mybrowseraddon, webbrowsertools, etc.) — broad external linkage with no CSP.
  • Rating 3.6 on a 2M-install extension suggests user dissatisfaction; no review red-flags captured but low rating is a quality signal.

Evidence

  • install_url_hijack + uninstall_url_hijack both true crx Extension registers onInstalled and setUninstallURL hooks to undisclosed targets — standard monetization shell pattern.
  • privacy_policy generic Google account policy store scope_extension=false, data_collection=true, third_party_sharing=true → D clause: +10.0 privacy pillar.
  • developer email is gmail.com free-webmail store grephyr.prj@gmail.com; no business domain; domain_age_ct not queried (free_webmail_or_no_email).
  • host_permissions <all_urls> + content_scripts <all_urls> manifest Full page access on every site; broad reach for a dark-mode theme extension.
  • 8 external JS hosts, no CSP (MV3) crx Hosts: github.com, jakiestfu.com, mjijackson.com, mybrowseraddon.com, opensource.org, stackoverflow.com, webbrowsertools.com, youtube.com.
  • is_featured_by_google = true store Featured badge partially mitigates reputation; not verified publisher.
  • rating 3.6 on 2M installs store Below-average rating at massive scale; no specific review red-flags detected.
  • operator_cluster dev_email sibling_count=4 api Same gmail address linked to 4 sibling extensions by dev_email dimension.

Permissions Breakdown

  • storage low Stores user preferences locally; low risk.
  • contextMenus low Adds right-click menu items; low risk.
  • <all_urls> (host_permissions) high Content script injection on every site; broad reach for a theme tool.

Pillar Scores

Permissions3.50
Reputation7.00
Network2.00
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedn0f581a0cdp727562726963xsx 5.14 Medium review 2026-09-08
<fsssiedxi xx psssiedx 4.49 Medium review 2026-08-20
<fsssiedxi'sssiedx 4.84 Medium review 2026-08-20
<fsssiedxi 4.73 Medium review 2026-08-20
<fsssiedxi$"sssiedx 5.20 Medium review 2026-08-20
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.78 Medium review 2026-08-20
<fsssiedxa xx psssiedx 4.42 Medium review 2026-08-20
<fsssiedxa 4.71 Medium review 2026-08-20
<fsssiedxa$'sssiedx 4.71 Medium review 2026-08-20
fsssiedx<sssiedx 5.13 Medium review 2026-08-20
sssieddrubricxsx 4.87 Medium review 2026-07-31
v3.6 4.85 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA 2cbca2f85980…
Force block — not fired
Score recovered no
Elapsed 24.0s