Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Free simple Adult Blocker with password

fgfoepffhjiinifbddlalpiamnfkdnim
Risk Score
5.43
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 2,000
Rating 4.8
Last updated 2025-02-17 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer kohl@adultblocker.org
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing without scoping to this extension — privacy pillar scores maximum.
  • Uninstall URL hijack to adultblocker.org/uninstall and install URL hijack — monetization/tracking signal.
  • Content scripts on <all_urls> with DOM-XSS innerHTML sink and no CSP — elevated code risk.
  • No developer name listed; verified publisher but 18 months since last update triggers discount cap (invariant 0c).
  • Broad host permission https://*/* combined with external JS host (reactjs.org CDN) and no CSP present.

Evidence

  • uninstall_url_hijack manifest chrome.runtime.setUninstallURL to https://adultblocker.org/uninstall — 3rd-party redirect on uninstall.
  • install_url_hijack manifest onInstalled opens https://adultblocker.org/install — 3rd-party URL on install.
  • privacy_policy_scope_extension_false api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers D rule (+10).
  • dom_sink_innerhtml_userctrl+no_csp crx innerHTML sink in popup.100f6462.js; csp_present=false triggers FIX B (+2.0 vs +0.5).
  • external_js_host_reactjs.org crx js_external_hosts includes reactjs.org — external CDN without CSP enforcement.
  • verified_publisher_stale_18mo store Verified publisher but months_since_update=18 triggers invariant 0c: discount capped at -1.0.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true: low-install count with high-tier host permissions.
  • no_developer_name store developer_name is empty; reputation penalty applied (+1.0).

Permissions Breakdown

  • alarms low Scheduled tasks; minimal standalone risk.
  • declarativeNetRequest medium Allows blocking/redirecting network requests — core to content-blocking function, but can intercept traffic.
  • tabs medium Access to tab URLs and metadata; enables surveillance of browsing activity.
  • storage low Local data persistence; low risk in isolation.
  • https://*/* high Broad host permission covering all HTTPS sites; paired with content_scripts on <all_urls>.
  • content_scripts:<all_urls> high Content scripts injected on every page; combined with DOM-XSS sink finding raises risk.

Pillar Scores

Permissions5.50
Reputation4.00
Network3.50
Webstore6.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:06
Listing SHA 4a6df3eff4a0…
Force block — not fired
Score recovered no
Elapsed