Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VU Quiz Firewall

gbiahfedloaennjklbmekkhoojlaffcc
Risk Score
5.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 70,000
Rating 1.8
Last updated 2024-12-13 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer faisalh@vu.edu.pk
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
  • management permission allows disabling/uninstalling other extensions — high-capability for a quiz tool.
  • Privacy policy is Google's generic account policy; not scoped to this extension; admits data collection and 3rd-party sharing.
  • Low rating (1.8) may indicate user-reported problems or forced-install friction.
  • Extension last updated 18 months ago; borderline stale for a security-adjacent tool.

Evidence

  • management permission manifest HIGH-tier: can enumerate and control all installed extensions — unusual for a quiz firewall.
  • generic Google privacy policy store URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true → D clause → +10.
  • low rating store Rating 1.8 — poor user satisfaction signal; no review red-flag text detected in structured data.
  • content_scripts scoped to vu.edu.pk manifest Three matches all within vu.edu.pk; narrow host access limits REACH.
  • developer identity store IT Dept, Virtual University of Pakistan; institutional .edu.pk domain resolves; not verified publisher.
  • maintenance staleness store months_since_update=18; maps to +6.0 maintenance pillar score.
  • no CSP manifest csp_present=false; MV3 default provides baseline protection but no explicit policy declared.
  • code quality clean crx code_findings_raw empty, obfuscation_score=0.0, no external JS hosts — no malicious code indicators.

Permissions Breakdown

  • storage low Standard local data persistence; low intrinsic risk.
  • management high Can enumerate, enable, disable, or uninstall other extensions — significant capability.
  • content_scripts: http://vds.vu.edu.pk/*, http://vulms.vu.edu.pk/*, https://vulms.vu.edu.pk/* medium Scoped to vu.edu.pk subdomains only; reads/modifies pages on VU LMS — narrow but sensitive for a quiz platform.

Pillar Scores

Permissions7.50
Reputation5.50
Network2.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA 09496c52a56a…
Force block — not fired
Score recovered no
Elapsed 20.9s