Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Better Lyrics (Lyrics for Youtube Music)

effdbpeggelllpfkjppbokhmmiinhlmg
Risk Score
2.76
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 70,000
Rating 4.9
Last updated 2026-06-13
Manifest version MV3
CSP present ✅ yes
Developer better-lyrics@boidu.dev
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope data collection to this extension at all.
  • Brand impersonation flag: extension name prominently references 'Youtube Music' without confirmed ownership.
  • 11 external JS hosts including third-party API endpoints (dacubeking.com, vercel.app); connect-src broad relative to stated function.
  • No developer display name listed in store, reducing accountability.
  • Privacy policy fetched AND admits data_collection=true and third_party_sharing=true with no extension scope.

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension. scope_extension=false, data_collection=true, third_party_sharing=true.
  • brand_impersonation store brand_mention.is_impersonation=true for 'youtube'; confirmed_owner=false. Verified publisher mitigates but does not eliminate.
  • verified_publisher_featured store Extension holds verified_publisher=true and is_featured_by_google=true, providing strong accountability signal.
  • external_hosts_count crx 11 distinct JS external hosts including dacubeking.com, vercel.app, betterlyrics.org, raw.githubusercontent.com, translate.googleapis.com.
  • no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; no eval, exfil, or remote-load findings.
  • no_cve_findings crx cve_findings_raw empty; no vulnerable bundled libraries detected.
  • narrow_permissions manifest Only storage and alarms declared; host_permissions scoped to music.youtube.com only. MV3.
  • no_threat_intel_hits api bad_host_hits, affiliate_hits, monetization_hits all empty; developer domain resolves and not throwaway.

Permissions Breakdown

  • storage low Used to persist user preferences; no sensitive data exposure.
  • alarms low Periodic task scheduling; minimal risk.
  • *://music.youtube.com/* (host) medium Scoped to single domain matching stated function; content injection on YouTube Music only.

Pillar Scores

Permissions1.00
Reputation3.50
Network3.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA 5a0e66ddd952…
Force block — not fired
Score recovered no
Elapsed 20.2s