Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

NordPass® Password Manager & Digital Vault

eiaeiblijfjekdanodkjadfinkhbfgcd
Risk Score
3.33
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Security
Installs 8,000,000
Rating 4.6
Last updated 2026-07-30 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@nordpass.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed (HTTP error); cannot verify scope or data handling — scored as no policy.
  • Broad host permissions (http://*/*, https://*/*) with scripting and webRequest grant full-page access on every site.
  • Privacy pillar scores maximum due to unverifiable policy, but this is a fetch artifact not confirmed bad practice.
  • webRequest + broad host access without blocking capability is still high-capability for a credential-handling extension.
  • Not verified_publisher on Web Store despite being a recognized commercial product; featured badge partially offsets.

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false due to fetch_error:HTTPError; scored +10.0 per rubric (fetched==false).
  • featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied (Follows recommended practices badge).
  • broad_host_permissions manifest host_permissions=['http://*/*','https://*/*'] plus content_scripts on same scope; justified for password manager autofill.
  • no_code_findings crx code_findings_raw=[] and obfuscation_score=0.0; 113 JS files scanned cleanly.
  • no_cve_findings crx cve_findings_raw=[]; no bundled vulnerable libraries detected.
  • no_threat_intel_hits api bad_host_hits=[], affiliate_hits=[], monetization_hits=[]; developer domain nordpass.com resolves and not throwaway.
  • high_install_good_rating store 7,000,000 installs, rating 4.6; no review red flags detected (match_count=0).
  • justified_broad_discount manifest Category=Security/PasswordManager; -1.5 justified-broad-permission discount applied to permissions pillar.

Permissions Breakdown

  • alarms low Used for periodic session/token refresh tasks.
  • contextMenus low Adds right-click fill options; standard for password managers.
  • idle low Detects inactivity for auto-lock; expected in password managers.
  • privacy high Can modify Chrome privacy settings; powerful but expected for security tools.
  • storage low Stores encrypted vault data locally.
  • tabs medium Reads active tab URL for credential matching; standard for autofill.
  • webNavigation medium Monitors navigation events to trigger autofill on page load.
  • webRequest high Observes network requests; justified for form-detection but elevated capability.
  • offscreen low Used for background crypto operations without visible UI.
  • scripting medium Injects autofill scripts into pages; required for credential filling.
  • http://*/* high Broad host access across all HTTP sites for autofill injection.
  • https://*/* high Broad host access across all HTTPS sites for autofill injection.

Pillar Scores

Permissions4.50
Reputation2.50
Network2.00
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

v3.69886"();}]9009 3.14 Low review 2026-08-05
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 3.09 Low review 2026-08-05
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 2.88 Low review 2026-08-05
v3.6&n937533=v957363 3.25 Low review 2026-08-05
v3.6</script><script>FUBG(9214)</script> 3.06 Low review 2026-08-04
dfb__${98991*97996}__::.x 2.84 Low review 2026-08-04
bfg8293<s1﹥s2ʺs3ʹhjl8293 3.08 Low review 2026-08-04
v3.6&n914483=v972893 3.09 Low review 2026-08-04
<fsssiedxa sssiedx 3.54 Low review 2026-08-03
xx pfsssiedxasssiedx 3.10 Low review 2026-08-03
"fsssiedxa xx psssiedx 3.46 Low review 2026-08-03
%22fsssiedxa$'sssiedx 3.21 Low review 2026-08-03
%27fsssiedxa sssiedx 3.05 Low review 2026-08-03
&#x27;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.00 Low review 2026-08-03
&#x22;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.41 Low review 2026-08-03
$"fsssiedxa&#x22;sssiedx 3.34 Low review 2026-08-03
fsssiedxa$"sssiedx 3.07 Low review 2026-08-03
v3.6"><script>tbvF(9626)</script> 3.36 Low review 2026-07-29
v3.6"onmouseover=tbvF(90682)" 2.73 Low review 2026-07-29
bfgx7346%C0%BEz1%C0%BCz2a%90bcxhjl7346 3.26 Low review 2026-07-29
<th:t="${dfb}#foreach 3.16 Low review 2026-07-29
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hittfbyowbcxle308f.bxss.me")}} 3.47 Low review 2026-07-29
v3.6&n910418=v906344 3.02 Low review 2026-07-29
fsssiedxa sssiedx 3.04 Low review 2026-07-28
fsssiedxa"sssiedx 2.96 Low review 2026-07-28
fsssiedxa 3.06 Low review 2026-07-28
fsssiedxa$'sssiedx 3.14 Low review 2026-07-28
sssieddrubricxsx 3.11 Low review 2026-07-28
v3.6 3.33 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA ac4d7d0141ba…
Force block — not fired
Score recovered no
Elapsed 25.6s