Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Github Profile

eijnkinhnplaekpllmgbbfieecdhcmcp
Risk Score
6.74
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category DeveloperTools
Installs 10
Rating
Last updated 2022-05-14 (51 months ago)
Manifest version MV2
CSP present ❌ no
Developer moonrailgun@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Extension abandoned 51 months ago (>36mo stale, MV2, no CSP) — maximum maintenance risk.
  • Privacy policy is generic Google account policy: admits data collection + 3rd-party sharing without extension scope.
  • Brand impersonation: mentions 'github' but developer is unaffiliated gmail user.
  • No CSP + MV2 + innerHTML sinks in both content_script and vendor.js — XSS surface unmitigated.
  • webRequest on github.com by unverified dev with no privacy policy and 6 external JS hosts including Heroku/Vercel badges.

Evidence

  • maintenance_stale store Last updated May 2022; 51 months stale — >36mo bracket scores 10.0 on maintenance pillar.
  • privacy_generic_google_policy crx Privacy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — scores 10.0.
  • brand_impersonation store brand_mention.is_impersonation=true for 'github'; developer is gmail, confirmed_owner=false.
  • no_csp_mv2 manifest MV2 + csp_present=false: +2.0 Network per v2 calibration; DOM sinks unmitigated.
  • dom_sink_innerhtml crx Two innerHTML sinks (content_script.js, vendor.js) with no CSP and no eval — each scores +2.0 under FIX B.
  • small_install_high_perm store install_perm_anomaly: 10 installs, HIGH-tier webRequest + broad host permission — tail attack surface flag.
  • external_js_hosts crx 6 external JS hosts: heroku, vercel, github, reactjs.org, laobi.icu; 2 countries (HK, US).
  • free_webmail_dev store Developer email moonrailgun@gmail.com; no verified publisher, no business website — Reputation floor 7.5.

Permissions Breakdown

  • https://*.github.com/* high Broad host access to all github.com subdomains; enables content script injection and data read.
  • webRequest high Can observe all network requests to github.com; combined with host access amplifies risk.
  • content_scripts: https://github.com/* medium Injects JS into github.com pages; consistent with stated function but elevates DOM attack surface.

Pillar Scores

Permissions3.50
Reputation7.50
Network4.50
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:04
Listing SHA a3811747882d…
Force block — not fired
Score recovered no
Elapsed