Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

FlipHTML5 | AnyFlip Downloader & Converter to PDF, EPUB & DOCX

fejalehlkcncbmmaeljpnjdffjjkildd
Risk Score
4.11
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 3,000
Rating 2.4
Last updated 2026-08-27 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer exportmyinfohq@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail developer (gmail) with no developer name and privacy policy on unrelated domain ext-boost.com.
  • Broad https://*/* host permission grants access to all HTTPS sites, far beyond anyflip/fliphtml5 targets.
  • identity.email permission harvests Google account email; no justification for a document downloader.
  • No CSP declared (MV3 default, but no explicit policy) + innerHTML sink in popup.js raises DOM-XSS risk.
  • Description promises download functionality but lacks 'downloads' permission — capability mismatch signal.

Evidence

  • free_webmail_dev_no_name store Developer email is exportmyinfohq@gmail.com with no developer_name; elevated identity-risk per rubric.
  • broad_host_permission manifest host_permissions includes https://*/* despite content_scripts scoped only to anyflip.com/fliphtml5.com.
  • identity_email_permission manifest identity.email declared; unnecessary for a PDF/EPUB converter — collects Google account email.
  • privacy_policy_third_party_sharing api Policy on ext-boost.com discloses data collection and third-party sharing but omits retention details.
  • dom_xss_sink crx innerHTML used with variable input in popup.100f6462.js; no CSP to mitigate DOM-XSS.
  • description_promise_mismatch store Extension promises download capability but lacks the 'downloads' permission in manifest.
  • low_rating store Rating 2.4 — below 3.0 threshold; indicates user dissatisfaction.
  • external_host_api_ext_api_com crx js_external_hosts includes api.ext-api.com — unrelated third-party API endpoint for a document downloader.

Permissions Breakdown

  • storage low Stores local extension state; limited blast radius.
  • identity medium OAuth token access; can fingerprint signed-in Google account.
  • identity.email medium Exposes user's Google email address to extension.
  • tabs medium Can read tab URLs and titles across all open tabs.
  • activeTab low Scoped to user-activated tab; lower risk than broad host access.
  • https://*/* high Broad host permission covering all HTTPS sites; high reach.

Pillar Scores

Permissions5.50
Reputation6.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:09
Listing SHA fe48d67f33ae…
Force block — not fired
Score recovered no
Elapsed