Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Invite fans and post likers in Facebook™

eiamkpbeehcnmbilkjkflelnendbmmhi
Risk Score
3.56
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 20,000
Rating 4.9
Last updated 2026-05-11 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@invitelikecomment.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses Facebook™ trademark; confirmed_owner=false yet is_impersonation=true.
  • No developer name disclosed; only an email under invitelikecomment.com.
  • scripting + host_permissions on *.facebook.com enables JS injection into user Facebook sessions.
  • No CSP (MV3 strict default mitigates, but no explicit policy declared).
  • Privacy policy lacks retention disclosure and is silent on third-party sharing.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[facebook]; confirmed_owner=false.
  • no_developer_name store developer_name is empty string; identity relies solely on email info@invitelikecomment.com.
  • host_permissions_facebook manifest host_permissions=['https://*.facebook.com/*']; scripting permission enables JS injection.
  • verified_publisher store verified_publisher=true; provides some accountability but does not override impersonation risk.
  • privacy_policy_gaps api scope_extension=true, data_collection=false, retention=false, third_party_silence=true.
  • js_external_hosts crx 7 external hosts referenced (bugzilla.mozilla.org, learn.jquery.com, www.invitelikecomment.com, etc.).
  • no_csp manifest content_security_policy=null; MV3 strict default applies but no explicit policy set.
  • jquery_version crx jquery@3.5.1 bundled; no CVEs found in cve_findings_raw; no CSP but MV3 mitigates.

Permissions Breakdown

  • storage low Local state persistence; low standalone risk.
  • activeTab medium Grants transient access to current tab; combined with scripting raises scope.
  • scripting medium Allows programmatic JS injection into pages; powerful when paired with host_permissions.
  • alarms low Background scheduling only; minimal direct risk.
  • https://*.facebook.com/* high Broad host access to all Facebook subdomains; enables reading session data and DOM.

Pillar Scores

Permissions3.50
Reputation6.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy6.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA 9d9295c3fa04…
Force block — not fired
Score recovered no
Elapsed 20.4s