Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Karma | Online shopping, but better

emalgedpdlghbkikiaeocoblajamonoh
Risk Score
2.92
Risk Level: Low
Recommendation: ✅ ALLOW
Category Shopping
Installs 500,000
Rating 4.6
Last updated 2026-08-25
Manifest version MV3
CSP present ❌ no
Developer support@karmanow.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • webRequest + broad host access (<all_urls>) enables full request observation across every site visited.
  • scripting + broad host access allows arbitrary JS injection on all HTTP/HTTPS pages.
  • No CSP on MV3 extension with 8 external JS hosts including tinyurl.com and github.com.
  • innerHTML DOM-XSS sink in hermesSDK.js without CSP guard — exploitable if data is attacker-influenced.
  • Privacy policy discloses third-party data sharing; shopping extension contacts 8 distinct external domains.

Evidence

  • broad_host_permissions manifest host_permissions: http://*/* and https://*/* grant access to every site.
  • webRequest_broad manifest webRequest declared with all-URL host permissions — full request observation capability.
  • no_csp crx content_security_policy is null; no script-src restriction on MV3 extension.
  • external_hosts crx 8 distinct external JS hosts including tinyurl.com, github.com, fe-evas.fih.io, vio.com.
  • dom_xss_sink crx innerHTML assignment in js/hermesSDK.js — DOM-XSS risk, amplified by absent CSP.
  • verified_publisher_featured store Extension is verified publisher and featured by Google; reputation floored at 2.0.
  • privacy_policy_third_party api Policy fetched, scoped, retention disclosed, but third_party_sharing == true adds +1.0 privacy.
  • geo_diversity crx JS hosts span 3 countries (CA, IN, US); below threshold of 4 for geo-diversity penalty.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; paired with broad host access increases sensitivity.
  • scripting high Programmatic script injection into pages; broad host access makes this near-universal.
  • webRequest high Observe all browser requests across all sites; core tracking/monitoring capability.
  • storage low Local data persistence only; low standalone risk.
  • http://*/* high Broad host access over HTTP for all sites.
  • https://*/* high Broad host access over HTTPS for all sites.

Pillar Scores

Permissions5.50
Reputation2.00
Network3.50
Webstore2.00
Maintenance0.00
Privacy1.00
Code Quality0.50
CVE Exposure0.00

Scoring History

fsssiedxn5fa3f2b4za'n5fa3f2b4zsssiedx 3.36 Low review 2026-08-30
sssiedn8a5300e8dp727562726963xsx 2.73 Low review 2026-08-30
v3.6 2.92 Low allow 2026-06-16
v3.4-rev 2.96 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA c63f8b58d876…
Force block — not fired
Score recovered no
Elapsed 34.7s