Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Urban AdBlocker

feflcgofneboehfdeebcfglbodaceghj
Risk Score
2.73
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Adblock
Installs 40,000
Rating 4.5
Last updated 2026-07-13 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer developer@urban-vpn.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • webRequest + <all_urls> + scripting gives full traffic interception capability on every site visited.
  • Explicit redirect API host_permission (api-pro.urban-vpn.com/rest/v1/redirect/) could enable traffic manipulation.
  • Remote config endpoint (config-toolbar.urban-vpn.com) allows server-side rule changes without extension update.
  • new Function() constructor found in content and service worker scripts; low obfuscation but dynamic eval risk.
  • No CSP declared (MV3 default applies); combined with function_constructor findings slightly elevates code risk.

Evidence

  • webRequest + <all_urls> manifest webRequest permission combined with <all_urls> host access gives full network interception on every page.
  • redirect API host_permission manifest api-pro.urban-vpn.com/rest/v1/redirect/* explicitly declared; enables server-directed traffic redirection.
  • remote config endpoint manifest config-toolbar.urban-vpn.com in host_permissions allows server to push config/filter changes dynamically.
  • function_constructor x2 crx new Function() found in content script and service worker; one is webpack boilerplate, one evaluates expressions.
  • is_featured_by_google store Google Featured badge reduces reputation risk; not verified publisher but featured.
  • privacy policy store Scoped policy with data_collection, retention, third_party_sharing all disclosed; adequate.
  • no CVEs, no bad hosts, no monetization hits api threat_intel and cve_findings_raw both empty; no known malicious infrastructure detected.
  • justified-broad-permission discount applied manifest Category=Adblock; broad host access + webRequest match stated function per rubric discount.

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata; medium risk for an adblocker needing page context.
  • webNavigation medium Tracks navigation events across all pages; used legitimately for filter timing.
  • storage low Stores filter lists and user preferences locally.
  • alarms low Schedules filter-list updates; low risk.
  • scripting medium Can inject scripts into pages; paired with <all_urls> this is broad capability.
  • webRequest high Intercepts all network requests; core to ad blocking but also enables surveillance.
  • declarativeNetRequest medium Declarative blocking; safer than webRequestBlocking but still broad.
  • <all_urls> high Host access to every site visited; justified for adblocker but high capability.
  • https://api-pro.urban-vpn.com/rest/v1/redirect/* high Explicit redirect API endpoint in host_permissions raises concern about traffic manipulation.
  • https://authentication.urban-vpn.com/* medium Auth backend access; acceptable for account-linked product.
  • https://anti-phishing-protection-toolbar.urban-vpn.com/* medium Contacts anti-phishing backend; plausible for security feature.
  • https://config-toolbar.urban-vpn.com/* medium Remote config endpoint; could push rule changes without extension update.

Pillar Scores

Permissions5.50
Reputation3.50
Network2.00
Webstore1.00
Maintenance0.00
Privacy0.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:45
Listing SHA c4d8fb91ef82…
Force block — not fired
Score recovered no
Elapsed