Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Kastemer

ecimbckphddmmgndcogbedhflgefdkfl
Risk Score
4.19
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs
Rating
Last updated 2024-11-25 (21 months ago)
Manifest version MV3
CSP present ❌ no
Developer labs.dev.crew@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL unreachable (fetch error) — effective no-policy situation, score 10.
  • Gmail developer account with no verified publisher — low accountability.
  • Content script on WhatsApp Web can read message DOM; innerHTML sink present (DOM-XSS risk).
  • Extension is 21 months stale — elevated supply-chain/abandonment risk.
  • No CSP declared (MV3 default is strict, but external host reactjs.org in JS is concerning).

Evidence

  • privacy_policy_fetch_failed api kastemer.com/privacy-policy/ returned ConnectionError — policy treated as unfetched, score +10.
  • free_webmail_developer store Developer email labs.dev.crew@gmail.com — free webmail, no verified business domain.
  • content_script_whatsapp manifest Content script injected into https://web.whatsapp.com/* — access to message DOM.
  • dom_xss_sink crx innerHTML assigned from variable in main.js; no CSP to mitigate DOM-XSS.
  • stale_extension store Last updated November 2024, 21 months ago — 6-12mo bracket (+3.5) plus approaching 24mo.
  • external_js_host crx js_external_hosts includes reactjs.org — reference site, not CDN, but unusual as external host.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false — no trust anchor.
  • install_count_missing store Install count not available — blast radius unknown.

Permissions Breakdown

  • storage low Standard local data persistence; low risk.
  • unlimitedStorage low Expands storage quota; minimal standalone risk.
  • *://*.kastemer.com/* low Narrow host permission scoped to developer's own domain only.
  • content_scripts: https://web.whatsapp.com/* medium Injects JS into WhatsApp Web; can read DOM including messages.

Pillar Scores

Permissions1.50
Reputation6.50
Network0.00
Webstore0.00
Maintenance6.00
Privacy10.00
Code Quality0.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:42
Listing SHA f750aab89f5c…
Force block — not fired
Score recovered no
Elapsed