Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Volume Booster

ejkiikneibegknkgimmihdpcbcedgmpo
Risk Score
5.01
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 2,000,000
Rating 4.2
Last updated 2026-07-12 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer alexanderkcheng@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, yet admits data collection and third-party sharing (Privacy pillar 10.0).
  • Uninstall URL hijacks to jointoucan.com affiliate link — classic monetization shell signal (+3.0 Webstore).
  • Broad host permissions (<all_urls> tripled) paired with tabCapture enables full audio/page capture on every site visited.
  • Developer email is free-webmail (gmail), no developer name, no business domain — low identity accountability.
  • No CSP declared (MV3 mitigates somewhat, but no_developer_name + gmail + broad permissions raises residual concern).

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://jointoucan.com/partners/volumebooster (affiliate/monetization redirect).
  • privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • broad_host_permissions manifest http://*/*, https://*/*, and <all_urls> all declared simultaneously — redundant and maximally broad.
  • free_webmail_dev_no_name store Developer email alexanderkcheng@gmail.com, developer_name empty; no business domain identity.
  • verified_publisher_featured store Both verified_publisher=true and is_featured_by_google=true; discounts applied but capped due to monetization signal.
  • js_external_host crx jointoucan.com referenced as external JS host — same domain as affiliate uninstall URL.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension.
  • tab_capture_all_urls manifest tabCapture + <all_urls> content_scripts enables audio capture on every site user visits.

Permissions Breakdown

  • tabCapture high Can capture audio/video from any tab — core function but high capability.
  • activeTab medium Access to currently active tab content on user interaction.
  • offscreen low Offscreen document for audio processing; low standalone risk.
  • storage low Stores extension settings locally.
  • unlimitedStorage low No storage quota; low direct risk.
  • windows low Window enumeration; low risk.
  • http://*/* high Broad host access to all HTTP sites.
  • https://*/* high Broad host access to all HTTPS sites.
  • <all_urls> high Catch-all host permission — redundant triple coverage amplifies risk.

Pillar Scores

Permissions7.00
Reputation4.50
Network2.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:17
Listing SHA 7f17ddeef085…
Force block — not fired
Score recovered no
Elapsed