Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Web paint

ejllkedmklophclpgonojjkaliafeilj
Risk Score
4.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 50,000
Rating 4.9
Last updated 2025-12-10 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer paintonweb@outlook.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Google generic privacy policy used — not scoped to this extension, admits data collection and 3rd-party sharing (D rule: +10.0 privacy).
  • Content scripts injected on <all_urls> with innerHTML DOM-XSS sinks in both index.js and options.js; no CSP to mitigate.
  • Free-webmail developer (outlook.com) with no developer name; identity unverifiable despite verified-publisher badge.
  • Broad host_permissions *://*/*ombined with content scripts gives full page read/write capability on every site.
  • React 16.13.1 bundled; older React versions have known XSS-adjacent issues, no CSP protection present.

Evidence

  • privacy_policy_generic store Policy is Google's own account privacy policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
  • dom_xss_sink_no_csp crx innerHTML sinks in index.js and options.js; csp_present=false triggers +2.0 code quality per FIX B rule.
  • broad_host_permissions manifest host_permissions *://*/* + content_scripts <all_urls>; HIGH capability on all sites.
  • free_webmail_no_dev_name store developer_email=paintonweb@outlook.com, developer_name empty; verified_publisher caps reputation floor at 2.0.
  • verified_publisher_featured store Both verified_publisher and is_featured_by_google true; applied reputation discounts but floored at 2.0.
  • react_16_no_csp crx React 16.13.1 bundled; no CSP. v2 calibration: react<16.4 amplifier not triggered (16.13.1 > 16.4) but innerHTML risk noted.
  • maintenance_3_6mo store months_since_update=8; falls in 6-12 month band → +3.5 maintenance.
  • js_external_hosts crx External JS host references: fb.me, mui.com, reactjs.org — documentation/CDN URLs, no bad-host hits.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles across all tabs.
  • storage low Local data persistence; limited standalone risk.
  • activeTab low Access limited to user-activated tab; low risk.
  • *://*/* high Broad host access to all URLs; enables content injection on any site.
  • content_scripts:<all_urls> high JS injected into every page; combined with innerHTML sinks raises XSS risk.

Pillar Scores

Permissions4.50
Reputation2.00
Network0.00
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:50
Listing SHA 7b8bd231468e…
Force block — not fired
Score recovered no
Elapsed