Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Directo - Travel Deals - Save on Hotels

fonalplhodhnenmokepaijoemaednpjm
Risk Score
3.22
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Shopping
Installs 300,000
Rating 4.5
Last updated 2026-09-03
Manifest version MV3
CSP present ✅ yes
Developer yourfriends@getdirecto.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • webRequest + broad host access (<all_urls>) enables observation of all user HTTP traffic across every site.
  • scripting + broad host access allows arbitrary JS injection into any page the user visits.
  • new Function() constructor in background.js and options.js; dynamic code execution risk.
  • No developer name listed; identity accountability gap for a 300K-install extension.
  • identity.email grants access to signed-in Google account email; PII collection risk.

Evidence

  • broad_host_permissions manifest host_permissions includes http://*/* and https://*/* — all sites reachable.
  • webRequest_broad manifest webRequest permission paired with <all_urls> enables full request interception.
  • function_constructor_background crx new Function() in js/background.js — dynamic code execution in privileged service worker context.
  • dom_sink crx innerHTML assigned from variable in js/vendor.js; DOM-XSS sink present.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity for a 300K-install extension.
  • featured_by_google store is_featured_by_google=true provides partial trust signal but no verified publisher badge.
  • monetization_telemetry crx google-analytics.com in js_external_hosts; classified as telemetry only, low tier.
  • privacy_policy_adequate api Policy fetched, scoped to extension, discloses data collection, retention, and third-party sharing.

Permissions Breakdown

  • storage low Standard local data persistence; low risk.
  • unlimitedStorage low Extends storage quota; minimal direct risk.
  • webRequest high Can observe all HTTP requests across all sites — high surveillance capability.
  • identity medium Access to Chrome identity API; can initiate OAuth flows.
  • identity.email medium Reads the signed-in Google account email; user PII.
  • activeTab low Scoped to user-activated tab; limited reach alone.
  • scripting medium Programmatic script injection into pages; high impact with broad host access.
  • alarms low Background scheduling only; low direct risk.
  • http://*/* high Broad host access over all HTTP sites — amplifies webRequest and scripting.
  • https://*/* high Broad host access over all HTTPS sites — amplifies webRequest and scripting.

Pillar Scores

Permissions7.50
Reputation4.50
Network2.00
Webstore2.50
Maintenance0.00
Privacy0.00
Code Quality3.50
CVE Exposure0.00

Scoring History

sssiedn4300fd82dp727562726963xsx 4.15 Medium review 2026-09-07
v3.6 3.22 Low review 2026-07-21

Bookkeeping

Rubric v3.6
Scored at 2026-07-21 03:41
Listing SHA 792598129ffc…
Force block — not fired
Score recovered no
Elapsed