Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

My Clipboard

emhmaepmgpjnimnogbehplipclejinpa
Risk Score
5.18
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 3,000
Rating 3.7
Last updated 2021-03-26 (63 months ago)
Manifest version MV3
CSP present ❌ no
Developer reed@myclipboard.io
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but does NOT scope to this extension, admits data collection AND third-party sharing — worst-case policy (+10.0 privacy).
  • Extension last updated 63 months ago (March 2021) — effectively abandoned, maintenance score 10.0.
  • install_url_hijack flag is true; onInstalled may open a third-party URL.
  • Developer name field is empty; reduced accountability.
  • clipboardRead permission captures potentially sensitive clipboard contents with no scoped data-handling disclosure.

Evidence

  • privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • maintenance_stale store 63 months since last update → maintenance pillar = 10.0.
  • install_url_hijack crx install_url_hijack=true; target null but flag set — onInstalled opens external URL.
  • developer_name_missing store developer_name is empty string; no 'Offered by' display name.
  • verified_publisher store verified_publisher=true; discount applies but capped at -1.0 due to staleness >18mo (invariant 0c).
  • no_csp crx content_security_policy is null; MV3 strict default applies, no v2 penalty.
  • cve_findings_empty crx No CVEs detected; cve_pillar_score = 0.0.
  • code_findings_empty crx No malicious code signals; obfuscation_score=0.0; code_quality = 0.0.

Permissions Breakdown

  • storage low Stores clipboard data locally; expected for this category.
  • clipboardRead medium Reads clipboard contents; core function but sensitive data exposure risk.

Pillar Scores

Permissions2.30
Reputation3.50
Network0.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA a4c145e7e663…
Force block — not fired
Score recovered no
Elapsed 19.2s