Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dopni - Automatic Cashback Service

ekafoahfmdgaeefeeneiijbehnbocbij
Risk Score
6.79
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Shopping
Installs 11
Rating 5.0
Last updated 2021-05-19 (63 months ago)
Manifest version MV2
CSP present ❌ no
Developer support@dopni.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned extension (63 months stale, MV2) with broad cookies+*://*/* access — high takeover/abuse risk.
  • Privacy policy URL returns fetch error; effectively no policy — max privacy score.
  • cookies + *://*/* combo on a cashback extension enables full session-cookie exfiltration across all sites.
  • No CSP on MV2 extension with DOM-XSS innerHTML sink in popup.js.
  • Only 11 installs with HIGH-tier permissions — tail-attack-surface anomaly flagged.

Evidence

  • broad_host_plus_cookies manifest cookies + *://*/* declared together; ×1.2 multiplier applied — can read session tokens on every site.
  • maintenance_stale store 63 months since last update (>36mo) — MV2 zombie extension; +10.0 maintenance pillar.
  • privacy_policy_fetch_error api privacy_policy_classification.fetched==false (HTTPError); policy URL unreachable — scored +10.0 privacy.
  • no_csp_mv2 manifest csp_present==false on MV2 manifest; +2.0 network per v2 calibration fix (b).
  • dom_sink_innerhtml crx popup.js: innerHTML assignment from variable; no CSP present → +2.0 code quality (FIX B).
  • install_perm_anomaly api 11 installs + HIGH-tier perms: small_install_high_perm=true, tail_attack_surface=true.
  • triple_stale_fingerprint store >24mo + MV2 + no CVEs found but still stale; +2.0 webstore triple-stale per v2 fix (c).
  • no_verified_publisher store verified_publisher=false, is_featured=false; no reputation discounts applicable.

Permissions Breakdown

  • declarativeContent low Allows conditional page-action display; low standalone risk.
  • storage low Local key-value storage; low risk.
  • tabs medium Access to tab URLs and metadata; moderate sensitivity.
  • activeTab medium Temporary access to current page; medium when combined with broad host perms.
  • cookies high Can read/write all cookies across all sites — high exfil potential.
  • *://*/* high Broad host access; allows content injection and data reads on every site visited.

Pillar Scores

Permissions8.00
Reputation5.00
Network4.00
Webstore4.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:09
Listing SHA e5259f8ef22c…
Force block — not fired
Score recovered no
Elapsed