Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ePub Reader for Google Chrome™

fnplkbhndemgbopkkpmpnfklkhphpneg
Risk Score
4.01
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category ReaderMode
Installs 200,000
Rating 3.2
Last updated 2026-08-06
Manifest version MV?
CSP present ❌ no
Developer alexeystore4@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: title uses 'Google Chrome™' trademark; developer is unverified gmail user with no confirmed ownership.
  • Privacy policy admits data collection and third-party sharing without scoping to this extension — worst-case disclosure.
  • Free-webmail dev email (alexeystore4@gmail.com) with no verified business domain raises accountability concerns.
  • manifest_source is html_fallback — actual permissions unknown, CRX not inspected.
  • 200K installs at 3.2 rating with no business identity creates significant reach with low governance.

Evidence

  • brand_impersonation store Title contains 'Google Chrome™'; brand_mention.is_impersonation=true, confirmed_owner=false, dev domain is gmail.com.
  • free_webmail_dev store Developer email alexeystore4@gmail.com is free webmail; no business website verifiable.
  • privacy_policy_generic_admit api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy score (v3.5 rule D).
  • manifest_html_fallback store manifest_source=html_fallback with 200K installs; actual permissions not inspectable — partial data risk.
  • low_rating store Rating 3.2; no review red flags matched but below 4.0 threshold suggests user dissatisfaction.
  • is_featured_by_google store Extension carries Google Featured badge, partially mitigating reputation risk despite unverified publisher.
  • no_code_surface crx js_files_scanned=0, obfuscation_score=0.0, code_findings_raw empty — CRX not analysed, code quality defaulted to 0.
  • operator_cluster_clean api sibling_count=0; no related extensions under same fingerprint detected.

Pillar Scores

Permissions0.00
Reputation7.50
Network0.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

fsssiedxa xx psssiedx 4.04 Medium review 2026-08-08
fsssiedxa 4.56 Medium review 2026-08-08
sssieddrubricxsx 4.28 Medium review 2026-08-08
v3.6 4.01 Medium review 2026-07-08

Bookkeeping

Rubric v3.6
Scored at 2026-07-08 12:00
Listing SHA dfaa55587c1d…
Force block — not fired
Score recovered no
Elapsed