Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Analytics & Ad Blocker: Open Source Privacy Firewall

fapldghopmonkbgaaiinpeopokpkhbmk
Risk Score
5.45
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Adblock
Installs 839
Rating 4.2
Last updated 2026-02-17 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer fintab.help@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope to this extension, yet admits data collection and third-party sharing (Privacy = 10.0).
  • Developer uses free Gmail address with no developer name and no business domain; low accountability.
  • Content script injected on <all_urls> combined with cookies permission; high reach on every site.
  • install_url_hijack: onInstalled opens options page, minor but flags engagement-optimization intent.
  • small_install_high_perm anomaly flagged: 839 installs with high-tier permissions is a tail-attack-surface indicator.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
  • developer_identity_weak store developer_name empty, email is free Gmail (fintab.help@gmail.com); no verified publisher badge.
  • content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] injects into every page; no host_permissions but reach is broad.
  • cookies_permission manifest cookies permission declared; combined with all_urls content script raises read risk.
  • function_constructor crx new Function() in options.bundle.js; potential code execution from string input.
  • install_url_hijack crx onInstalled opens options.html?tab=about; low-severity engagement pattern.
  • install_perm_anomaly api small_install_high_perm=true; 839 installs with high-tier permissions flagged.
  • external_hosts crx Contacts safebrowsing.googleapis.com and stuk.github.io; stuk.github.io is a third-party JS host.

Permissions Breakdown

  • storage low Local config/settings storage; low risk.
  • activeTab medium Access to current tab on user action; limited scope.
  • declarativeNetRequest medium Network request blocking/modifying; appropriate for Adblock category.
  • declarativeNetRequestFeedback medium Read match feedback on blocked requests; minor information exposure.
  • cookies high Cookie read/write; no broad host_permissions but still sensitive.
  • content_scripts:<all_urls> high Script injected into every page; high reach even without host_permissions.

Pillar Scores

Permissions5.50
Reputation7.00
Network3.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA ffd9b225e3e1…
Force block — not fired
Score recovered no
Elapsed 23.5s