Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Email Finder by Snov.io

einnffiilpmgldkapbikhkeicohlaapj
Risk Score
3.57
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 400,000
Rating 4.9
Last updated 2026-05-22 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer help@snov.io
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad <all_urls> host_permissions + cookies permission allows reading/modifying any site and its cookies.
  • No CSP declared (MV3 default applies) with DOM innerHTML sink in bootstrap.min.js — XSS risk if input escapes sanitizer.
  • 10 external JS hosts contacted including snovio.cn (alternate TLD), twitter.com, and Google Analytics.
  • Uninstall URL redirects to app.snov.io — minor redirect risk but noted.
  • install_url_hijack flag set; install behavior should be verified for unwanted redirects.

Evidence

  • broad_host_permissions manifest host_permissions include http://*/ and https://*/ — content scripts injected on all URLs.
  • cookies_high_perm manifest cookies permission combined with <all_urls> triggers ×1.2 amplifier.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; reputation floor 2.0.
  • dom_sink_innerhtml crx bootstrap.min.js contains innerHTML assignment from variable; no CSP to mitigate.
  • external_hosts_diversity crx 10 external hosts: snovio.cn, twitter.com, api.twitter.com, getbootstrap.com, github.com, bing, GA.
  • monetization_telemetry api Google Analytics hit (telemetry-tier only); qualifies for telemetry discount — +1.0 webstore.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL targets app.snov.io/uninstall/email-finder (own domain, lower risk).
  • privacy_policy_complete store Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles across all open tabs.
  • cookies high Access to cookies; paired with broad host_permissions elevates risk ×1.2.
  • notifications low Can show desktop notifications; limited standalone risk.
  • storage low Local extension storage; low standalone risk.
  • http://*/ high Broad HTTP host access — content scripts run on all HTTP sites.
  • https://*/ high Broad HTTPS host access — content scripts run on all HTTPS sites.

Pillar Scores

Permissions6.00
Reputation2.00
Network3.50
Webstore4.50
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA 1e10510713a4…
Force block — not fired
Score recovered no
Elapsed 23.9s