Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Moon: Shop online with Bitcoin

ehmpejjklcibliopgbghpgfinhbjopnn
Risk Score
4.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 9,000
Rating 4.4
Last updated 2023-02-13 (40 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@paywithmoon.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy could not be fetched (HTTP error); classification unknown — scored as no policy.
  • Extension not updated in 40 months (>36mo stale); abandoned/unmaintained risk.
  • No CSP present (MV3 default) combined with innerHTML DOM-XSS sink in app.js.
  • No developer name listed in store; reduced accountability.
  • Triple-stale fingerprint: >24mo + MV3 no CSP + DOM sink increases code quality concern.

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (fetch_error:HTTPError); scored as +10.0 privacy.
  • maintenance_stale store Last updated Feb 2023; months_since_update=40 (>36mo). Pillar=10.0.
  • dom_xss_sink crx app.js: innerHTML assigned from variable; no CSP present, raising code quality to 0.5.
  • no_developer_name store developer_name is empty string; Reputation +1.0 for no Offered-by name.
  • no_csp manifest content_security_policy is null; MV3 so no +2.0 network penalty, but dom sink elevated.
  • narrow_host_permissions manifest host_permissions and content_scripts scoped only to https://paywithmoon.com/*.
  • no_bad_hosts_or_affiliates api threat_intel bad_host_hits, affiliate_hits, monetization_hits all empty.
  • operator_cluster_clean api operator_cluster sibling_count=0; no sibling extensions detected.

Permissions Breakdown

  • storage low Stores local extension data; low risk.
  • activeTab medium Grants access to the currently active tab on user action; scoped but still tab access.
  • scripting medium Allows JS injection into pages; limited by narrow host_permissions to paywithmoon.com.
  • host: https://paywithmoon.com/* low Narrow host permission scoped only to developer's own domain; minimal blast radius.

Pillar Scores

Permissions1.30
Reputation5.00
Network0.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality0.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA 2f964ed033be…
Force block — not fired
Score recovered no
Elapsed 21.8s