Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Auto Refresh Plus

ffejlioijcokmblckiijnjcmfidjppdn
Risk Score
2.47
Risk Level: Low
Recommendation: ✅ ALLOW
Category Productivity
Installs 100,000
Rating 4.8
Last updated 2026-07-09 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer lukemartindev482@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad <all_urls> host permission with content_scripts on every site — high REACH if compromised.
  • Developer email is free-webmail (gmail) with no verified developer name; accountability gap.
  • No developer name listed; verified_publisher badge partially offsets but gmail identity remains weak.
  • js_external_hosts includes react.dev — external JS reference warrants scrutiny despite no bad-host hits.
  • MV3 with no CSP declared; csp_present=false adds minor network risk but no code findings found.

Evidence

  • host_permissions_all_urls manifest <all_urls> host permission paired with content_scripts on all URLs — maximum site reach.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; significant trust signals partially offset risks.
  • developer_email_free_webmail store lukemartindev482@gmail.com — numbered-alias gmail, no developer name, no verified business identity.
  • privacy_policy_scoped api Policy fetched, scope_extension=true, data_collection=true, retention=true, third_party_sharing=true — fully disclosed.
  • code_findings_clean crx 0 code findings, obfuscation_score=0.0, 4 JS files scanned — no malicious patterns detected.
  • cve_findings_empty crx No CVEs found in bundled libraries; no bad-host or monetization hits.
  • js_external_host_react_dev crx js_external_hosts includes react.dev alongside autorefreshplus.in; no threat-intel hits on either.
  • no_csp manifest csp_present=false on MV3; adds minor network surface but MV3 has strict defaults mitigating impact.

Permissions Breakdown

  • storage low Stores user settings; low impact alone.
  • <all_urls> (host_permissions) high Content scripts injected on every site; broad reach for page manipulation.
  • <all_urls> (content_scripts_matches) high Script runs on every page load; high data access surface.

Pillar Scores

Permissions4.50
Reputation4.50
Network2.00
Webstore2.50
Maintenance0.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:10
Listing SHA b3ec05f34d5e…
Force block — not fired
Score recovered no
Elapsed