Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Wrike ToDo list

eopgmefbafmikfhhbdinpdpbiicbchce
Risk Score
3.72
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category NewTab
Installs 8,000
Rating 3.9
Last updated 2025-10-01 (8 months ago)
Manifest version MV3
CSP present ✅ yes
Developer chromewebstore@team.wrike.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension at all.
  • NewTab override: replaces every new-tab page; install_url_hijack redirects to chrome://newtab on install.
  • Developer domain team.wrike.com does not resolve, weakening accountability signal.
  • CSP allows cdn.jsdelivr.net for img-src and fonts.googleapis.com/fonts.gstatic.com for font/style; minor scope creep.
  • Rating 3.9 and no verified-publisher badge for a recognized SaaS vendor; unverified identity.

Evidence

  • privacy_policy_generic store Policy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers D rule (+10.0 privacy).
  • newtab_override manifest chrome_url_overrides.newtab = index.html; every new tab is controlled by this extension.
  • install_url_hijack crx onInstalled opens chrome://newtab (internal), not a 3rd-party URL; low monetization risk.
  • developer_domain_no_resolve api threat_intel.developer_domain_info.resolves=false for team.wrike.com; reduces accountability.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; Wrike is a known SaaS but not badge-verified here.
  • cve_findings_clean crx No CVEs detected; no bundled vulnerable JS libraries.
  • code_findings_clean crx code_findings_raw empty, obfuscation_score=0.0; no malicious code patterns.
  • threat_intel_clean api bad_host_hits, affiliate_hits, monetization_hits all empty; no ad-tech or threat hosts.

Permissions Breakdown

  • identity low Used for OAuth login flow to Wrike; no broad scopes declared.
  • storage low Local state persistence; low standalone risk.
  • tabs medium Can read tab URLs and titles; moderate risk without host access.
  • host: https://www.wrike.com/ low Scoped to developer's own domain; expected for task sync.
  • host: https://*.chromiumapp.org/* low Required for OAuth redirect flow in Chrome identity API.
  • chrome_url_overrides.newtab medium Replaces new-tab page; high-visibility surface, moderate risk.

Pillar Scores

Permissions2.30
Reputation4.50
Network1.50
Webstore4.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA e505b8b7543f…
Force block — not fired
Score recovered no
Elapsed 23.1s