Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

React Developer Tools

fmkadmapgofadopljbjfkapdkoienihi
Risk Score
2.07
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 6,000,000
Rating 3.9
Last updated 2025-10-22 (11 months ago)
Manifest version MV3
CSP present ✅ yes
Developer extensions@fb.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; collects+shares data per policy.
  • <all_urls> host permission with content_scripts on every site creates broad code-injection surface.
  • new Function() constructor in worker file enables dynamic code execution; low obfuscation mitigates.
  • developer_domain_info.looks_throwaway flagged for fb.com (likely false-positive heuristic, but noted).
  • No verified-publisher badge; Meta identity unverified by Chrome Web Store.

Evidence

  • broad_host_permissions manifest host_permissions: [<all_urls>] + content_scripts on <all_urls>; justified for DevTools but maximum site reach.
  • function_constructor_in_worker crx new Function() in build/importFile.worker.worker.js; isolated to file-import worker, likely for CommonJS module shim.
  • generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • featured_by_google store is_featured_by_google=true; follows recommended practices badge reduces but doesn't eliminate risk.
  • recognized_org_meta store developer_name=Meta, email=extensions@fb.com; fb.com resolves; high-capability gate applies (broad host+scripting).
  • no_bad_hosts_no_cves crx bad_host_hits=[], affiliate_hits=[], monetization_hits=[], cve_findings_raw=[]; clean threat-intel.
  • csp_present_mv3 manifest CSP: script-src 'self'; object-src 'self'. MV3 strict default; no remote script-src.
  • js_external_hosts crx External hosts in source: bugs.chromium.org, foo.com, react.dev — appear as reference URLs, not active fetch endpoints.

Permissions Breakdown

  • scripting medium Allows JS injection into pages; core to DevTools function but broad capability.
  • storage low Local preference/state storage; low risk.
  • tabs medium Access to tab URLs and metadata; needed for DevTools targeting.
  • <all_urls> (host_permissions) high Content scripts on all URLs; justified for a DevTools extension but broad reach.

Pillar Scores

Permissions4.50
Reputation3.00
Network0.00
Webstore1.00
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

sssiednfb8afc2cdp727562726963xsx 2.54 Low review 2026-09-05
fsssiedxn8a28e0c8za xx pn8a28e0c8zsssiedx 1.63 Low review 2026-08-25
sssiedne7081620dp727562726963xsx 2.65 Low review 2026-08-25
v3.69968/"();}]9492 1.43 Low review 2026-08-05
v3.6"onmouseover=PjbZ(97422)" 1.72 Low review 2026-08-05
bfgx3338%C0%BEz1%C0%BCz2a%90bcxhjl3338 1.58 Low review 2026-08-05
<th:t="${dfb}#foreach 1.49 Low review 2026-08-05
v3.6&n959136=v976912 2.54 Low review 2026-08-05
v3.6'"()&%<zzz><ScRiPt >4JCY(9918)</ScRiPt> 1.43 Low review 2026-07-29
v3.6&n971500=v972544 1.58 Low review 2026-07-29
v3.6 2.07 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA b75b6a467036…
Force block — not fired
Score recovered no
Elapsed 50.8s