Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

L.O.C

eojdckfcadamkapabechhbnkleligand
Risk Score
4.97
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 300,000
Rating 4.3
Last updated 2024-05-02 (25 months ago)
Manifest version MV3
CSP present ❌ no
Developer locmai88@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — worst-case disclosure.
  • cookies + broad Facebook/Messenger host_permissions enables Facebook session-token exfiltration.
  • Developer uses free Gmail address with empty developer_name field; low accountability.
  • install_url_hijack fires on install, redirecting users to loc.dev/dashboard — unsolicited navigation.
  • Extension is 25 months stale with 300K installs; abandoned high-reach tool is an acquisition target.

Evidence

  • privacy_policy_admits_third_party_sharing_unscoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0 (v3.5 rule D).
  • cookies_with_broad_facebook_host manifest cookies permission + https://*.facebook.com/* + https://*.messenger.com/* enables full session-cookie access.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens https://loc.dev/dashboard — unsolicited redirect on install (+2.0 Webstore).
  • free_webmail_no_developer_name store developer_email=locmai88@gmail.com, developer_name empty; free-webmail+no-name reputation floor applies.
  • stale_25_months store months_since_update=25; falls in 24-36mo band → Maintenance +8.5 before cap at 6.0 for MV3.
  • verified_publisher_with_stale_and_gmail store verified_publisher=true but months>18 and dev domain is gmail; v3.5 invariant 0c caps discount at -1.0.
  • lnmai_com_unknown_third_party manifest host_permissions include lnmai.com and mtfb.lnmai.com; no public identity; js_external_hosts confirms outbound reach.
  • no_csp manifest csp_present=false on MV3; v2 fix (b) applies +2.0 Network only for MV2; MV3 strict default mitigates.

Permissions Breakdown

  • notifications medium Can push notifications to user; medium nuisance/phishing vector.
  • cookies high Can read/write cookies for host_permissions domains (Facebook, messenger).
  • storage low Local extension storage only.
  • unlimitedStorage low Allows large local data; minor risk alone.
  • declarativeNetRequest medium Can block/redirect network requests; paired with host permissions raises concern.
  • https://*.messenger.com/* high Broad host access to Messenger; cookies permission amplifies session-theft risk.
  • https://*.facebook.com/* high Broad host access to Facebook; cookies permission amplifies session-theft risk.
  • https://loc.dev/* low Developer's own domain; expected for update/config calls.
  • https://lnmai.com/* medium Third-party domain with no clear public identity; unknown purpose.
  • https://mtfb.lnmai.com/* medium Subdomain of lnmai.com; unclear purpose, Facebook-like naming pattern.

Pillar Scores

Permissions6.50
Reputation7.00
Network3.50
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA 62ce937a0652…
Force block — not fired
Score recovered no
Elapsed 27.3s