Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

cPanel DNS Extractor

figncpfadmnmhdepglkckdfifdjdnalo
Risk Score
3.49
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 152
Rating
Last updated 2025-12-03 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@mizemedia.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and third-party sharing.
  • No content security policy (MV3 default is strict, but absence confirmed); scripting permission allows JS injection.
  • Description promises 'recording' but lacks capture permissions — minor permission/description mismatch.
  • Very low install count (152) with no ratings makes reputation unverifiable.
  • Developer identity unverified; no verified-publisher badge.

Evidence

  • privacy_policy_generic store Privacy policy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • description_promise_mismatch store description_promise.mismatches: 'promises recording but lacks tabCapture/desktopCapture' → +2.0 webstore.
  • no_csp manifest csp_present=false, MV3 — v2 fix (b) does not add penalty for MV3; strict default applies.
  • maintenance_3_6_months store months_since_update=6, in 3-6mo band → +1.5 maintenance.
  • low_installs_no_rating store 152 installs, 0 ratings — no popularity-as-trust discount applicable.
  • no_bad_hosts_no_cve crx bad_host_hits=[], cve_findings_raw=[], affiliate_hits=[], monetization_hits=[] — clean threat intel.
  • developer_domain_resolves api mizemedia.com resolves=true, looks_throwaway=false; business email on own domain.
  • code_clean crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[] — no malicious indicators.

Permissions Breakdown

  • activeTab low Scoped to user-initiated action on current tab only; limited blast radius.
  • scripting medium Allows JS injection into active tab; combined with activeTab scope, moderate risk.

Pillar Scores

Permissions1.30
Reputation5.00
Network2.00
Webstore2.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA 41427d53cb1a…
Force block — not fired
Score recovered no
Elapsed 20.8s