Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

JSON Viewer Pro

eifflpmocdbdmepbjaopkkhbfmdgijcc
Risk Score
5.26
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 300,000
Rating 4.7
Last updated 2025-04-15 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer rahulbaruri1@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • Broad *://*/* host permissions + content_scripts on all URLs including file:// and ftp:// give full page-read capability.
  • Developer uses free Gmail address with no business domain; no developer name listed.
  • install_url_hijack flag is true — extension opens a URL on install (target null, unable to confirm benign).
  • 14 months since last update raises supply-chain and abandonment risk at 300K installs.

Evidence

  • broad_host_permissions manifest host_permissions *://*/* + content_scripts on *://*/* file:/// ftp:/// — full read/write on every page.
  • privacy_policy_generic store Policy URL is myaccount.google.com; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
  • install_url_hijack crx install_url_hijack=true; target=null. Extension fires onInstalled redirect to unconfirmed destination.
  • dom_sink_innerhtml crx dom_sink_innerhtml_userctrl in js/main.js; no CSP; DOM-XSS risk from controlled input.
  • free_webmail_no_dev_name store developer_email=rahulbaruri1@gmail.com; developer_name empty; no business domain.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied but capped at -1.0 (monetization/staleness check: clean).
  • stale_14mo store 14 months since update; 300K installs; Maintenance +6.0.
  • no_csp manifest content_security_policy=null on MV3 extension; no CSP amplifies DOM-sink risk.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • storage low Local preference storage; no exfil risk alone.
  • *://*/* (host_permissions) high Broad host access; content_scripts also match all URLs including file/ftp.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA 894c8a9482ae…
Force block — not fired
Score recovered no
Elapsed 24.2s