Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

YT Zoom

gaanolhdjafoofiogciikoimdfakndjp
Risk Score
5.18
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 7,000
Rating 3.7
Last updated 2022-08-09 (46 months ago)
Manifest version MV3
CSP present ❌ no
Developer cholodymedia@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: mentions 'YouTube' and 'Zoom' — is_impersonation=true, not a verified publisher.
  • Privacy policy is Google's generic account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — worst-case privacy score.
  • Extension not updated in 46 months (>36mo); abandoned and maintenance score maxed.
  • Developer email is free Gmail with no verifiable business identity.
  • Featured badge partially mitigates reputation but does not override impersonation or privacy failures.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands ['youtube','zoom'] mentioned; developer_domain is gmail.com, not verified owner.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 per v3.5 rule D.
  • maintenance_abandoned store Last updated August 2022, 46 months ago (>36mo). Maintenance pillar = 10.0.
  • free_webmail_developer store Developer email cholodymedia@gmail.com; free webmail, no business website verifiable.
  • featured_by_google store is_featured_by_google=true; provides -2.0 reputation discount (featured badge).
  • no_csp manifest content_security_policy is null; MV3 so no +2.0 network penalty, but CSP absent.
  • content_scripts_scoped manifest content_scripts_matches=['https://www.youtube.com/*']; narrow scope matching stated function.
  • cve_none crx cve_findings_raw=[]; no CVE exposure detected.

Permissions Breakdown

  • content_scripts:https://www.youtube.com/* medium Injects script into YouTube pages; scoped to single domain, consistent with stated function.

Pillar Scores

Permissions1.00
Reputation7.50
Network0.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA 23f6a2d2fbcf…
Force block — not fired
Score recovered no
Elapsed 19.1s