Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Paint - Easy Drawings

doiiaejbgndnnnomcdhefcbfnbbjfbib
Risk Score
4.52
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 20,000
Rating 4.6
Last updated 2025-04-18 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer jjohnslemon@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL timed out — cannot verify any data handling disclosures; treated as no policy.
  • Broad host permission (*://*/*) paired with scripting allows script injection on any site.
  • Last updated 16 months ago; stale for an extension with broad host access.
  • Free-webmail developer (gmail.com), no developer name listed, reducing accountability.
  • MV3 with no CSP declared; no external hosts observed but no policy safety net.

Evidence

  • privacy_policy_fetch_failed api Privacy policy URL returned ConnectTimeout; classified as fetched=false → +10.0 privacy pillar.
  • broad_host_permission manifest host_permissions includes *://*/* giving access to all URLs combined with scripting API.
  • free_webmail_dev_no_name store Developer email jjohnslemon@gmail.com; developer_name empty; no verified business identity.
  • stale_extension store 16 months since last update; falls in 12-24mo band (+6.0 maintenance).
  • verified_publisher_featured store Extension carries verified_publisher=true and is_featured_by_google=true; reputation discount applied.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty; code quality clean.
  • no_cve_findings crx cve_findings_raw empty; no known vulnerable libraries bundled.
  • no_threat_intel_hits api bad_host_hits, monetization_hits, affiliate_hits all empty; no malicious network signals.

Permissions Breakdown

  • storage low Stores local drawing data; low risk for a paint app.
  • activeTab medium Access to current tab on user action; limited scope but enables page interaction.
  • scripting medium Can inject scripts into pages; paired with host_permissions elevates risk.
  • *://*/* high Broad host access covers all URLs; scripting+activeTab+this is a high-capability combo.

Pillar Scores

Permissions5.50
Reputation4.00
Network2.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:50
Listing SHA 440249cb7945…
Force block — not fired
Score recovered no
Elapsed