Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

To Discord

epcihifbffodmnbbnjgancnlodhbkhcl
Risk Score
4.09
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 2,000
Rating 4.2
Last updated 2025-02-07 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer hj2931996@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — no extension-specific disclosure.
  • Brand impersonation: 'discord' mentioned, developer not a confirmed owner, gmail-only contact with no business website.
  • No developer name and free-webmail email with no business domain raise identity/accountability concerns.
  • No CSP declared (MV3 strict default mitigates somewhat, but no explicit policy increases code-injection surface).
  • Stale at 16 months since last update; moderately elevated abandonment risk.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=['discord'], confirmed_owner=false, dev domain=gmail.com.
  • privacy_policy_generic api Policy URL is Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_identity store developer_name empty, developer_email=hj2931996@gmail.com (free webmail), no business website.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; applies reputation discount but capped by impersonation.
  • no_csp manifest content_security_policy=null; MV3 defaults apply but no explicit CSP declared.
  • maintenance store months_since_update=16; falls in 3.5 band (6-12mo boundary crossed at 12mo → +6.0 maintenance).
  • low_permissions manifest Only activeTab, contextMenus, storage declared; no host_permissions or content_scripts_matches.
  • cve_clean crx cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[].

Permissions Breakdown

  • activeTab low Only accesses current tab on user gesture; no persistent host access.
  • contextMenus low Adds right-click menu entries; minimal standalone risk.
  • storage low Local key-value storage for Discord channel configs; low risk.

Pillar Scores

Permissions0.90
Reputation6.50
Network2.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA cdb885d4dc91…
Force block — not fired
Score recovered no
Elapsed 20.1s