Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Email checker - verify email address in 1-click

eheagnmidghfknkcaehacggccfiidhik
Risk Score
4.79
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 563
Rating 3.7
Last updated 2024-10-19 (22 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@email-checker.pro
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — unscoped, admits data collection & 3rd-party sharing; scores maximum 10.
  • Install URL hijack: onInstalled opens https://email-checker.pro/welcome (+2.0 Webstore).
  • Uninstall URL hijack declared (+3.0 Webstore).
  • Extension is 22 months stale (>18mo), triggering maintenance penalty and capping verified-publisher discount.
  • No developer name listed, reducing accountability despite verified-publisher badge.

Evidence

  • install_url_hijack crx onInstalled opens https://email-checker.pro/welcome — unsolicited tab open on install.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() declared; target not resolved but flag is true.
  • generic_privacy_policy store Policy URL is Google's own privacy page (myaccount.google.com), not scoped to this extension; data_collection=true, third_party_sharing=true.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity visible.
  • verified_publisher_capped store verified_publisher=true but months_since_update=22 (>18mo) caps discount to -1.0 per invariant 0c/3.5E.
  • stale_extension store 22 months since last update; maintenance score 6.0 (12-24mo band).
  • external_js_host crx js_external_hosts: ['email-checker.pro'] — extension contacts developer domain at runtime.
  • csp_absent_mv3 manifest content_security_policy is null; MV3 has strict defaults so no Network penalty applied, but no explicit CSP.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • storage low Local key-value storage only; no exfil risk alone.

Pillar Scores

Permissions0.60
Reputation5.50
Network0.00
Webstore7.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:54
Listing SHA 75534af98fef…
Force block — not fired
Score recovered no
Elapsed