Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

YouTube Time Manager

fpoooibdndpjcnoodfionoeakeojdjaj
Risk Score
5.24
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 9,000
Rating 3.8
Last updated 2024-07-13 (23 months ago)
Manifest version MV3
CSP present ❌ no
Developer avi6106@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail dev with no business identity lists Google's own privacy policy — policy not scoped to this extension at all.
  • Brand impersonation: uses 'YouTube' in name/title with no Google affiliation confirmed.
  • External hosts include PayPal plan-verification and matchmaking/promotion Cloud Run endpoints — unexpected for a time manager.
  • No CSP on MV3 extension contacting 9 distinct external hosts including cloud functions and PayPal APIs.
  • 23 months since last update; approaching zombie threshold with unverifiable backend endpoints.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=[youtube], confirmed_owner=false, developer domain=gmail.com.
  • generic_privacy_policy store Policy is Google's own account policy (scope_extension=false, data_collection=true, third_party_sharing=true). +10.0 Privacy per v3.5 rule D.
  • suspicious_external_hosts crx verifypaypalplanid-*.run.app, updatematchmakingpromotiontest-*.run.app, createorfetchusertest-*.run.app — atypical for a YouTube timer.
  • no_csp manifest content_security_policy=null; MV3 default is stricter but no explicit policy declared; +2.0 Network (MV2+no-CSP rule not applicable to MV3).
  • free_webmail_dev_no_name store developer_email=avi6106@gmail.com, developer_name=''. Reputation floor >=7.5 per rubric.
  • maintenance_risk store 23 months since update; +6.0 maintenance score (6-24mo band).
  • network_host_count crx 9 distinct external registrable domains contacted; >3 distinct domains triggers +1.5 Network.
  • verified_publisher_claimed store verified_publisher=true but dev email is gmail; cap -1.0 discount applies per 0c (months_since_update=23>18).

Permissions Breakdown

  • storage low Standard local data persistence; low risk.
  • unlimitedStorage low Extends storage quota; minimal risk alone.
  • identity low OAuth identity without scopes; moderate concern if used with cloud backend.
  • https://*.youtube.com/* medium Host permission scoped to YouTube only; consistent with stated function.

Pillar Scores

Permissions1.30
Reputation8.00
Network4.50
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA be4240456b9c…
Force block — not fired
Score recovered no
Elapsed 23.9s