Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DNS Checker - SEO and Domain Analysis

gegfpbhjnhegdnjdkghhnneaocdbbhjp
Risk Score
5.93
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 20,000
Rating 4.5
Last updated 2025-07-01 (11 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@softrixtech.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + <all_urls> + webRequest: can read cookies and observe requests on every site the user visits.
  • Privacy policy URL returned HTTP error (fetch_error) — policy could not be verified; scored as unfetched (+10).
  • brand_mention.is_impersonation=true (Meta mentioned) by unverified publisher — potential brand abuse.
  • Uninstall URL hijack detected — extension registers a 3rd-party uninstall redirect.
  • No CSP + innerHTML user-controlled sink: DOM-XSS risk amplified by absence of content security policy.

Evidence

  • broad_host_cookies_webrequest manifest cookies + webRequest + <all_urls> + content_scripts *://*/* — full read access to all sites and cookies.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (fetch_error:HTTPError) — policy unverifiable, scored +10.
  • brand_impersonation store brand_mention.is_impersonation=true, brands=[meta], not verified/featured publisher.
  • uninstall_url_hijack crx uninstall_url_hijack=true — extension sets uninstall redirect URL to 3rd party.
  • no_csp_innerhtml_sink crx csp_present=false AND dom_sink_innerhtml_userctrl in popup.min.js — DOM-XSS risk elevated.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true — partial trust signal.
  • developer_name_missing store developer_name is empty string — no visible 'Offered by' name in listing.
  • no_csp_mv3 manifest MV3 extension with no content_security_policy declared — no strict CSP protections.

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata across all open tabs.
  • cookies high Can read/write cookies; paired with <all_urls> this is maximum-reach cookie access.
  • storage low Extension-local storage only.
  • webRequest high Can observe all HTTP request details across all sites.
  • activeTab low Limited to currently active tab on user gesture.
  • *://*/* high Broad host permission granting access to all HTTP/HTTPS sites.
  • <all_urls> high Redundant broad host access; covers all schemes including file://.
  • content_scripts *://*/* high Content scripts injected into every page the user visits.

Pillar Scores

Permissions8.00
Reputation5.00
Network4.00
Webstore5.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA 54043b91b951…
Force block — not fired
Score recovered no
Elapsed 25.5s