Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Canvas Blocker & Fingerprint Protect

gbkicngmnoedeajgodbbokjadbfbbpng
Risk Score
2.88
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category PrivacyTool
Installs 147
Rating
Last updated 2026-08-25 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer binderpo343@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (binderpo343@gmail.com) with generic name 'ChromeExtensions' — low accountability.
  • Content scripts run on <all_urls> giving broad reach despite minimal declared permissions.
  • Privacy policy hosted on free Google Sites; lacks data retention disclosure.
  • Description claims ad-blocking but lacks declarativeNetRequest/webRequest — promise/permission mismatch.
  • Very low install count (147) with no ratings — no community vetting signal.

Evidence

  • developer_email_free_webmail store Dev email binderpo343@gmail.com with generic name 'ChromeExtensions'; no verified business identity.
  • content_scripts_all_urls manifest content_scripts_matches includes <all_urls>; JS injected on every page visited.
  • privacy_policy_free_hosting_no_retention api Policy on sites.google.com; scope_extension=true, data_collection=true, retention=false.
  • description_promise_mismatch store Description promises ad-blocking but no declarativeNetRequest or webRequest permission present.
  • no_ratings_low_installs store 147 installs, 0 ratings — no community trust signal available.
  • third_party_silence api Privacy policy does not address third-party data sharing despite data_collection=true.
  • no_code_findings crx 0 code findings, obfuscation_score=0.0, no external JS hosts — clean static scan.
  • no_bad_host_hits api threat_intel shows no bad hosts, monetization hits, or affiliate hits.

Permissions Breakdown

  • storage low Stores extension settings locally; no cross-origin data access.
  • content_scripts <all_urls> medium Injects JS on every site; broad reach even without host_permissions API access.

Pillar Scores

Permissions1.30
Reputation7.00
Network0.00
Webstore4.00
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 15:53
Listing SHA 5cafdcbd1ba5…
Force block — not fired
Score recovered no
Elapsed