Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Helcim Payment Extension

fndndkhhipkehljpeljojhjappfmdkpf
Risk Score
4.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 1,000
Rating 5.0
Last updated 2026-06-12
Manifest version MV3
CSP present ✅ yes
Developer developers@helcim.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed; cannot confirm data handling scope for a payment-integrated extension.
  • cookies permission + scripting across 40+ third-party SaaS domains is high-capability surface area.
  • Dynamic script injection (script_src_dynamic) found in sidepanel.js and bundled Pendo SDK.
  • External JS hosts include Pendo analytics (agent.pendo.io) and Datadog CDN; telemetry reaches third parties.
  • Not a verified publisher; helcim.com resolves but no Web Store verification badge.

Evidence

  • privacy_policy_fetch_failed api fetch_error:HTTPError on https://legal.helcim.com/us/privacy-policy/; privacy pillar scored at max 10.0.
  • cookies_broad_host manifest cookies permission paired with 40+ host_permissions covering major SaaS platforms.
  • script_src_dynamic crx Dynamic <script> injection in sidepanel.js and pendo.js; +3.0 code quality.
  • external_telemetry_hosts crx agent.pendo.io, datadoghq CDN contacted; legitimate analytics but increases network surface.
  • no_verified_publisher store verified_publisher=false; no Google featured badge; reputation starts at 5.0.
  • csp_present_mv3 manifest CSP restricts script-src to self; connect-src allows Helcim API + Pendo + Datadog.
  • no_bad_hosts_no_affiliates api threat_intel shows no bad_host_hits, affiliate_hits, or monetization_hits.
  • recently_updated store months_since_update=0; maintenance pillar score 0.0.

Permissions Breakdown

  • activeTab low Limited to user-initiated tab interaction.
  • storage low Local extension data storage.
  • sidePanel low UI surface only, low risk.
  • scripting medium Can inject scripts into host-permission pages; meaningful capability.
  • tabs medium Can read tab URLs and metadata.
  • cookies high Can read/write cookies on all host-permission domains including SaaS platforms.
  • webNavigation medium Observes navigation events across scoped domains.
  • alarms low Scheduling only, no data access.
  • host_permissions (40+ SaaS domains) high Broad access to 40+ third-party SaaS platforms; cookies+scripting on all.

Pillar Scores

Permissions6.50
Reputation4.50
Network4.50
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality3.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA c3011c11b03f…
Force block — not fired
Score recovered no
Elapsed 25.7s