Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ad Library - Save Facebook TikTok - Foreplay

eaancnanphggbfliooildilcnjocggjm
Risk Score
4.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 20,000
Rating 4.9
Last updated 2026-06-04
Manifest version MV3
CSP present ❌ no
Developer zach@foreplay.co
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension title mentions Facebook and TikTok; confirmed_owner=false.
  • Privacy policy fetched but scope_extension=false with data_collection=true and third_party_sharing=true — worst-case generic policy.
  • Content scripts injected on Facebook, Instagram, TikTok, LinkedIn, YouTube, and ChatGPT with no CSP — broad data-read surface.
  • No CSP (MV3 default enforced, but csp_present=false increases exfil risk given broad host access).
  • Developer name absent; description_promise.is_shell_pattern=true raises function-vs-permission scrutiny.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands facebook/tiktok in title; confirmed_owner=false; not verified publisher.
  • privacy_policy_generic api scope_extension=false, data_collection=true, third_party_sharing=true — policy admits sharing but not scoped to extension.
  • broad_host_permissions manifest Content scripts on 6 major platforms (FB, IG, TikTok, LinkedIn, YouTube, ChatGPT) plus foreplay.co R2.
  • no_csp manifest content_security_policy=null; MV3 provides defaults but no explicit CSP declared.
  • shell_pattern store description_promise.is_shell_pattern=true; developer_name empty; only 'storage' declared perm with broad host access.
  • featured_by_google store is_featured_by_google=true; provides partial trust signal offsetting some reputation risk.
  • no_bad_hosts_no_cves crx bad_host_hits=[], cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0 — clean scan.
  • js_external_hosts crx 12 external hosts including ads.tiktok.com, adstransparency.google.com, securetoken.google.com — all appear functionally justified.

Permissions Breakdown

  • storage low Standard local data persistence; minimal risk.
  • *://*.facebook.com/* high Content script on Facebook; can read/modify all page content including credentials.
  • *://*.instagram.com/* high Content script on Instagram; broad read/write page access.
  • *://*.tiktok.com/* high Content script on TikTok; broad read/write page access.
  • *://*.linkedin.com/* high Content script on LinkedIn; can read professional/personal data.
  • *://*.youtube.com/* medium Content script on YouTube; beyond stated ad-library saving function.
  • *://*.chatgpt.com/* medium Content script on ChatGPT; not explained by ad-saving stated purpose.
  • *://*.r2.foreplay.co/* low Dev-controlled CDN/storage domain; expected for saving ads.

Pillar Scores

Permissions3.50
Reputation5.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA 678e93f82216…
Force block — not fired
Score recovered no
Elapsed 24.2s