Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tasks - To do & task list by Workona

dneiffjipkkinmcpploifdknmhlmfbhc
Risk Score
3.54
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 30,000
Rating 4.8
Last updated 2024-06-18 (24 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@workona.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy covers workona.com broadly but does not scope data collection to THIS extension; admits 3rd-party sharing.
  • Extension not updated for 24 months — at boundary of stale threshold.
  • No CSP defined (MV3 mitigates somewhat, but adds minor risk surface).
  • Developer name field empty in manifest; reduces accountability signal.
  • Privacy policy scores max (10) due to scope_extension=false + data_collection=true + third_party_sharing=true per v3.5 D rule.

Evidence

  • privacy_policy_scope_mismatch api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → generic policy admitting 3rd-party sharing.
  • maintenance_stale store Last updated June 2024; months_since_update=24, triggering +6.0 maintenance score.
  • no_csp manifest content_security_policy is null; MV3 provides default CSP but no explicit policy declared.
  • featured_by_google store is_featured_by_google=true; follows recommended practices badge provides -2.0 reputation discount.
  • clean_threat_intel api No bad_host_hits, affiliate_hits, or monetization_hits. Developer domain workona.com resolves, not throwaway.
  • clean_code crx code_findings_raw empty, obfuscation_score=0.0, no CVEs detected in 2 scanned JS files.
  • scoped_host_permissions manifest Host permissions limited to workona.com and *.workona.com only; no broad host access.
  • no_operator_cluster api sibling_count=0; no related suspicious extensions under same fingerprint.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; limited scope with only workona.com host access.
  • storage low Local data persistence for task list; standard productivity use.
  • host: https://workona.com/* low Scoped to developer-owned domain only; expected for sync functionality.
  • host: https://*.workona.com/* low Subdomain wildcard on dev-owned domain; reasonable for backend API calls.

Pillar Scores

Permissions1.30
Reputation3.50
Network2.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA 520e92e98aaf…
Force block — not fired
Score recovered no
Elapsed 20.3s