Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AHA Music - Song Finder for Browser

dpacanjfikmhoddligfbehkpomnbgblf
Risk Score
4.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 1,000,000
Rating 4.2
Last updated 2026-05-07 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer contact@aha-music.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but does NOT scope to this extension, admits data collection AND third-party sharing → Privacy pillar 10.0.
  • tabCapture permission can record audio/video of any browser tab; content_scripts on *://*/* maximises reach.
  • cookies permission combined with broad content script reach creates session-theft surface.
  • Third-party host extension.doreso.com in host_permissions is not the developer's own domain.
  • sandbox.js uses new Function() constructor; sandbox CSP allows unsafe-eval, weakening isolation.

Evidence

  • privacy_policy_scope_mismatch api Policy fetched (98 KB), scope_extension=false, data_collection=true, third_party_sharing=true → score +10.0.
  • tabCapture+content_scripts_all_urls manifest tabCapture can record tab audio/video; content_scripts injected on *://*/* amplifies reach.
  • cookies_permission manifest cookies declared alongside broad content-script reach; session exfil risk.
  • third_party_host_doreso manifest host_permissions includes https://extension.doreso.com/* — unverified third-party analytics/service.
  • function_constructor_sandbox crx new Function() in sandbox.js; sandbox CSP permits unsafe-eval — weakens sandboxing.
  • verified_publisher_featured store Extension is verified publisher AND featured by Google; reputation floor 2.0 applied.
  • csp_host_cluster_20 api csp_host_set sibling_count=20: same CSP host fingerprint shared with 20 other extensions.
  • no_developer_name store developer_name field is empty; verified publisher badge partially offsets but display name missing.

Permissions Breakdown

  • identity low OAuth identity flow; limited scope without identity.email alone is moderate but paired here.
  • identity.email medium Accesses the user's Google account email address; PII exposure risk.
  • storage low Standard local data persistence.
  • unlimitedStorage low Allows unbounded local storage; low direct risk but can cache sensitive data.
  • activeTab low Scoped to user-activated tab; limited blast radius.
  • tabCapture high Can capture audio/video of any browser tab; core to song-detection but high-capability.
  • cookies high Broad cookie read/write access; paired with host_permissions on aha-music.com and doreso.com.
  • https://*.aha-music.com/* low Scoped to own first-party domain.
  • https://extension.doreso.com/* medium Third-party domain not clearly owned by developer; fingerprinting/analytics risk.
  • content_scripts: *://*/* high Content script injected on every page; broad reach for audio detection but wide attack surface.

Pillar Scores

Permissions5.50
Reputation2.00
Network2.50
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

sssiedn2b0c0e17dp727562726963xsx 3.86 Low review 2026-09-07
<fsssiedxa&#x22;sssiedx 2.72 Low review 2026-08-20
<fsssiedxa$'sssiedx 3.44 Low review 2026-08-20
fsssiedxa<sssiedx 3.72 Low review 2026-08-20
fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.09 Medium review 2026-08-20
sssieddrubricxsx 3.89 Low review 2026-08-20
%F6"onmouseover=kgjH(93315)// 2.63 Low review 2026-08-05
<%={{={@{#{${dfb}}%> 3.84 Low review 2026-08-05
bfg9163<s1﹥s2ʺs3ʹhjl9163 4.00 Medium review 2026-08-05
v3.6&n964573=v961310 4.07 Medium review 2026-08-05
v3.69499/"();}]9630 4.07 Medium review 2026-07-29
v3.6"sTYLe='zzz:Expre/**/SSion(j4xw(9252))'bad=" 4.54 Medium review 2026-07-29
%76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%6A%34%78%77%28%39%35%35%37%34%29%22 4.56 Medium review 2026-07-29
v3.6" BUek=j4xw([!+!]) uPL=" 2.72 Low review 2026-07-29
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 4.18 Medium review 2026-07-29
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 3.64 Low review 2026-07-29
bfg4160<s1﹥s2ʺs3ʹhjl4160 3.61 Low review 2026-07-29
dfb{{98991*97996}}xca 3.61 Low review 2026-07-29
v3.69826095 4.28 Medium review 2026-07-29
v3.6'"()&%<zzz><ScRiPt >j4xw(9073)</ScRiPt> 4.07 Medium review 2026-07-29
v3.6 4.27 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA a03b076f5c21…
Force block — not fired
Score recovered no
Elapsed 27.6s