Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

fdpohaocaechififmbbbbbknoalclacl

fdpohaocaechififmbbbbbknoalclacl
Risk Score
3.28
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Screenshot
Installs
Rating
Last updated
Manifest version MV?
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false and data_collection=false — policy does not address this extension specifically.
  • No CSP defined (MV3 default strict but no explicit CSP); 3 innerHTML DOM-XSS sinks present in page-injected and welcome scripts.
  • install_url_hijack=true — onInstalled opens an external URL; target is null so destination unknown.
  • No developer name listed; only email on dev-owned domain gofullpage.com.
  • months_since_update unknown — staleness cannot be confirmed; maintenance risk defaulted to mid-range.

Evidence

  • install_url_hijack crx install_url_hijack=true, target=null; onInstalled redirects to unknown external URL.
  • privacy_policy_scope api Policy fetched (56 chars) but scope_extension=false, data_collection=false — too short to be meaningful.
  • dom_xss_sinks crx 3 innerHTML assignments from variables in page-injected script and welcome bundle; no CSP to mitigate.
  • description_mismatch store Description promises 'recording' but lacks tabCapture/desktopCapture permissions.
  • no_developer_name store developer_name is empty; identity relies solely on support@gofullpage.com email.
  • featured_by_google store is_featured_by_google=true; follows recommended practices badge applies.
  • no_cve_findings crx cve_findings_raw is empty; React 16.13.1/17.0.2 bundled but no flagged CVEs.
  • maintenance_unknown store last_updated and months_since_update are null; staleness cannot be assessed.

Permissions Breakdown

  • activeTab medium Access to current tab on user action — limited scope but enables page content read.
  • scripting medium Can inject scripts into pages; paired with activeTab keeps scope narrow.
  • storage low Stores extension settings locally.
  • unlimitedStorage low Needed to store full-page screenshots; no extra data-access capability.

Pillar Scores

Permissions2.00
Reputation3.50
Network0.00
Webstore3.50
Maintenance3.50
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssieddrubricxsx 2.00 Low review 2026-07-31
v3.6 3.28 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA 044c5a211c18…
Force block — not fired
Score recovered no
Elapsed 24.5s