Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Quick CSS inspector

eoneeaafigemiemdbacdheajnlmklkci
Risk Score
5.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 34
Rating
Last updated 2023-12-04 (30 months ago)
Manifest version MV3
CSP present ❌ no
Developer silentsheep1919@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; data_collection and third_party_sharing admitted.
  • Extension is 30 months stale with no updates, raising abandonment/supply-chain risk.
  • Developer uses free Gmail with no verifiable business identity.
  • Content scripts injected on all HTTP/HTTPS pages despite DeveloperTools stated purpose.
  • No CSP declared (MV3 enforced, so no v2 penalty, but adds minor surface).

Evidence

  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
  • stale_extension store Last updated Dec 2023; months_since_update=30 → maintenance +8.5.
  • free_webmail_dev store Developer email silentsheep1919@gmail.com; free webmail, no business website → reputation +1.5.
  • broad_content_scripts manifest content_scripts_matches covers http://*/ and https://*/ — runs on all pages.
  • no_bad_hosts_no_cves crx cve_findings_raw empty, bad_host_hits empty, code_findings_raw empty — no active malicious signals.
  • low_install_count store Only 34 installs; install_perm_anomaly flags clear — tail exposure limited.
  • mv3_no_csp manifest csp_present=false but MV3 enforces strict CSP by default; no v2 network penalty applied.
  • no_operator_siblings api operator_cluster.sibling_count=0; no known extension farm pattern.

Permissions Breakdown

  • activeTab low Grants access only to the active tab on user interaction; limited blast radius.
  • scripting medium Allows injecting scripts into pages; combined with content_scripts broad match raises capability.
  • content_scripts http://*/ https://*/ medium Content scripts run on all HTTP/HTTPS pages; broad host reach even without declared host_permissions.

Pillar Scores

Permissions2.00
Reputation6.50
Network2.00
Webstore1.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA 68fa9756f4f4…
Force block — not fired
Score recovered no
Elapsed 20.1s