Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

YouTube High Definition

dokdlgjaaaijndfajoknjbelmadhomca
Risk Score
4.61
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 10,000
Rating 3.8
Last updated 2024-09-10 (23 months ago)
Manifest version MV3
CSP present ❌ no
Developer barisderin@yahoo.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • YouTube brand impersonation: developer is unverified yahoo.com user with no dev name.
  • host_permissions <all_urls> while content_scripts only cover youtube.com — scope mismatch grants unnecessary broad access.
  • Extension stale 21 months with no CSP, increasing future-compromise attack surface.
  • Free-webmail developer (yahoo.com), no business identity, no developer name disclosed.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'youtube'; developer is yahoo.com free-webmail user with no org affiliation.
  • generic_privacy_policy store Privacy policy is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — D clause triggers +10.0.
  • host_permission_all_urls manifest <all_urls> host permission declared; content_scripts only target youtube.com — scope mismatch.
  • no_csp manifest content_security_policy is null; MV3 has strict default but getbootstrap.com loaded as external JS host.
  • free_webmail_dev_no_name store developer_email=barisderin@yahoo.com, developer_name empty, no business website.
  • stale_21_months store Last updated Sep 2024; 21 months since update triggers +6.0 maintenance base.
  • external_js_host crx js_external_hosts includes getbootstrap.com — third-party JS origin loaded by extension.
  • verified_publisher_capped store verified_publisher=true but 0c cap applies: months_since_update=21 (>18), so discount capped at -1.0.

Permissions Breakdown

  • storage low Stores extension preferences locally; low standalone risk.
  • <all_urls> (host_permission) high Content scripts injected on all URLs; broad access beyond stated YouTube scope.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

<fsssiedx{ xx psssiedx 5.19 Medium review 2026-08-20
<fsssiedx{ 4.43 Medium review 2026-08-20
<fsssiedx{$"sssiedx 5.18 Medium review 2026-08-20
<fsssiedxhfdsaxax><!--></ScRiPt>asddsssiedx 5.17 Medium review 2026-08-20
<fsssiedxh 5.28 Medium review 2026-08-20
<fsssiedxh$"sssiedx 5.09 Medium review 2026-08-20
xx pfsssiedxmfdsaxax><!--></ScRiPt>asddsssiedx 5.39 Medium review 2026-08-20
"fsssiedxm xx psssiedx 4.48 Medium review 2026-08-20
%27fsssiedxm"sssiedx 5.37 Medium review 2026-08-20
%27fsssiedxm$"sssiedx 4.30 Medium review 2026-08-20
&#x27;fsssiedxm$'sssiedx 5.24 Medium review 2026-08-20
&#x22;fsssiedxm sssiedx 4.66 Medium review 2026-08-20
<fsssiedxm sssiedx 5.08 Medium review 2026-08-20
fsssiedxm<sssiedx 5.01 Medium review 2026-08-20
fsssiedxa xx psssiedx 5.36 Medium review 2026-08-20
fsssiedxa 5.49 Medium review 2026-08-20
sssieddrubricxsx 5.07 Medium review 2026-08-20
v3.6 4.61 Medium review 2026-06-16
v3.4-rev 4.86 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA afb8bc639938…
Force block — not fired
Score recovered no
Elapsed 20.2s