Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dark Mode for Chrome

epbpdmalnhhoggbcckpffgacohbmpapb
Risk Score
3.97
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Accessibility
Installs 60,000
Rating 4.5
Last updated 2025-02-21 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer bellowmaixinoom@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host permissions (*://*/*) with content scripts on every page — high-capability for a dark-mode tool.
  • Developer uses free Gmail address with no verified business identity; no dev name listed.
  • Privacy policy lacks retention clause; third-party sharing is silent.
  • Extension 16 months stale — supply-chain takeover risk window is open.
  • No CSP declared; elevated injection risk if future code changes occur.

Evidence

  • broad_host_permissions manifest host_permissions include *://*/* and content_scripts_matches *://*/* — runs on every page.
  • gmail_developer store Developer email bellowmaixinoom@gmail.com; no dev name; free webmail with no verified business.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied but capped at -1.0 (stale >12mo).
  • privacy_policy_retention_missing api Policy fetched, scoped, data_collection=true, but retention=false and third_party_silence=true.
  • no_csp manifest content_security_policy is null on MV3; +2.0 Network penalty applied.
  • maintenance_stale store Last updated Feb 2025, 16 months ago — 12-24mo band (+6.0 raw maintenance score).
  • no_bad_hosts_no_cves api threat_intel bad_host_hits=[], cve_findings_raw=[], code_findings_raw=[]; no active threat signals.
  • operator_cluster_clean api sibling_count=0; no affiliated sibling extensions detected.

Permissions Breakdown

  • fontSettings low Allows reading/changing browser font settings; limited blast radius.
  • activeTab low Scoped to current tab on user gesture; low standalone risk.
  • storage low Local preference storage; no exfil path alone.
  • tabs medium Exposes URL/title of all open tabs; moderate info-disclosure risk.
  • alarms low Scheduling only; no data access.
  • *://*/* high Broad host permission — content scripts injected on every HTTP/S page.
  • *://*/*/* high Redundant broad host permission; same surface as *://*/*.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.00
Webstore1.50
Maintenance6.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA 91ac9baf3fc0…
Force block — not fired
Score recovered no
Elapsed 24.2s