Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WProofreader: AI grammar check & rewrite tool

ehlmgkidbfjedfdanfechlikaolobpgh
Risk Score
5.39
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 4,000
Rating 4.0
Last updated 2026-06-09
Manifest version MV3
CSP present ❌ no
Developer support@webspellchecker.net
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed (HTTP error); cannot verify data handling for AI grammar tool processing all page text.
  • broad host permissions (http://*/*, https://*/*) + cookies + scripting enables reading page content and cookies on every site.
  • new Function() constructor in bundled JS (wscbundle.js) — dynamic code execution risk.
  • innerHTML assignment from variable (dom_sink_innerhtml_userctrl) with no CSP — potential DOM-XSS vector.
  • No developer name listed; uninstall URL hijack flag set with null target adds uncertainty.

Evidence

  • broad_host_permissions manifest http://*/* and https://*/* grant read/script access to every site visited.
  • cookies_high_perm manifest cookies permission paired with <all_urls> host access — ×1.2 amplifier applied.
  • no_csp crx content_security_policy is null; no CSP mitigates DOM-XSS findings.
  • function_constructor crx wscbundle.js: new Function() constructor used — dynamic code execution.
  • dom_sink_innerhtml_userctrl crx wscbundle.js: innerHTML assigned from variable with no CSP — +2.0 FIX B applies.
  • privacy_policy_fetch_failed api fetched==false (HTTPError); policy cannot be assessed — scored +10.0.
  • install_url_hijack store install_url_hijack=true with null target; minor concern without confirmed 3rd-party URL.
  • uninstall_url_hijack store uninstall_url_hijack=true with null target; cannot confirm 3rd-party redirect.

Permissions Breakdown

  • activeTab low Grants access to current tab on user action only.
  • tabs medium Can read tab URLs and metadata across browser.
  • storage low Local key-value storage; limited scope.
  • unlimitedStorage low Allows large local data; minor risk alone.
  • cookies high Can read/write cookies; paired with <all_urls> host access amplifies risk.
  • scripting high Programmatic script injection into pages; broad with <all_urls>.
  • http://*/* high Broad host access to all HTTP sites.
  • https://*/* high Broad host access to all HTTPS sites including banking/health.

Pillar Scores

Permissions7.00
Reputation5.00
Network4.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA 8794431e7785…
Force block — not fired
Score recovered no
Elapsed 26.9s