Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

fmjcdfedpdpgegomehbbdakblcdnkdfj

fmjcdfedpdpgegomehbbdakblcdnkdfj
Risk Score
6.07
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Other
Installs
Rating
Last updated
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • No developer identity: no name, email, or verified publisher — zero accountability.
  • Privacy policy is Google's generic policy — does not scope to this extension; data collection and third-party sharing admitted.
  • Content scripts on <all_urls> + broad host permission https://*/* allow reading/modifying every HTTPS page.
  • External JS hosts include api.ext-api.com and web.whatsapp.com — unknown third-party API with sensitive messaging platform access.
  • Manifest name/description are localization placeholders — extension identity is opaque; no update date available.

Evidence

  • no_developer_identity store developer_name, developer_email all empty; verified_publisher=false; is_featured=false.
  • generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • broad_host_access manifest host_permissions=[https://*/*] + content_scripts_matches=[<all_urls>] — reads/modifies every HTTPS page.
  • external_js_hosts crx Contacts api.ext-api.com (unknown API), web.whatsapp.com (messaging), reactjs.org, empty.invalid.
  • dom_xss_sink crx popup.100f6462.js: innerHTML assigned from variable — DOM-XSS sink; csp_present=false amplifies risk.
  • opaque_manifest manifest manifest_name=__MSG_name__, manifest_description=__MSG_description__ — no readable identity.
  • no_update_date api months_since_update=null, last_updated=null — maintenance posture unknown; scored conservatively.
  • identity_email_permission manifest identity + identity.email expose Google account identity; combined with broad host access raises exfil risk.

Permissions Breakdown

  • storage low Local data persistence; low standalone risk.
  • identity medium OAuth token access; can identify and authenticate user silently.
  • identity.email medium Exposes user's Google account email to the extension.
  • https://*/* high Broad host access across all HTTPS sites; content scripts can read/modify any page.
  • content_scripts:<all_urls> high Content scripts injected into every URL; full DOM read/write on all pages.

Pillar Scores

Permissions6.00
Reputation8.50
Network4.00
Webstore3.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:12
Listing SHA 6849aa685ed5…
Force block — not fired
Score recovered no
Elapsed