Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Total Adblock - Ad Blocker

gekdekpbfehejjiecgonmgmepbdnaggp
Risk Score
2.68
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Adblock
Installs 800,000
Rating 3.3
Last updated 2026-05-31 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@totalav.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false and admits third-party data sharing — GDPR/CCPA mismatch for enterprise.
  • Broad permission cluster: cookies+browsingData+contentSettings+webRequest+<all_urls> enables full session hijack if compromised.
  • new Function() constructor in 20 bundled JS files; no CSP to constrain dynamic code execution.
  • No CSP on MV3 extension; MV3 default strict-CSP should apply but absence increases risk surface.
  • Rating 3.3 with 900K installs and no developer display name; elevated post-compromise blast radius.

Evidence

  • privacy_policy_scope_mismatch api Policy fetched (36897 chars), scope_extension=false, data_collection=true, third_party_sharing=true — admits sharing without extension scope.
  • broad_host_permission manifest <all_urls> host permission paired with cookies, browsingData, webRequest, contentSettings.
  • function_constructor_widespread crx new Function() found in 20 of 77 JS files; consistent boilerplate pattern but present in background script.
  • no_csp manifest content_security_policy is null; no explicit CSP declared on MV3 extension.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; dev domain totalav.com resolves.
  • low_rating store Rating 3.3 with 900K installs; no review red flags detected by automated scan.
  • external_hosts crx js_external_hosts: link.adtidy.org (AdGuard filter lists), www. (truncated). No bad/monetization/affiliate hits.
  • no_cve_findings crx cve_findings_raw empty; jquery 3.6.3 bundled (no known CVEs at this version).

Permissions Breakdown

  • alarms low Scheduling only; minimal risk.
  • scripting high Injects scripts into pages; core adblocker function but high capability.
  • browsingData high Can delete cookies, cache, history — broad data erasure capability.
  • contentSettings high Can override per-site permissions (JS, cookies, plugins).
  • cookies high Read/write all cookies across all sites with <all_urls>.
  • notifications low Push notifications; low direct data risk.
  • storage low Local extension storage only.
  • tabs medium Access tab URLs and metadata across all open tabs.
  • unlimitedStorage low Removes storage quota; no direct privacy risk.
  • webRequest high Observes all network requests; paired with <all_urls> is high risk.
  • declarativeNetRequest medium Declarative request blocking; lower risk than webRequest.
  • webNavigation medium Monitors navigation events across all tabs.
  • <all_urls> high Broadest host access; amplifies every other high permission.

Pillar Scores

Permissions5.50
Reputation2.50
Network2.00
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

<fsssiedxa xx psssiedx 3.47 Low review 2026-08-17
<fsssiedxa&#x22;sssiedx 3.28 Low review 2026-08-17
xx pfsssiedxa sssiedx 3.33 Low review 2026-08-17
%27fsssiedxa$"sssiedx 3.29 Low review 2026-08-17
fsssiedxa$'sssiedx 3.52 Low review 2026-08-17
<fsssiedxa"sssiedx 3.42 Low review 2026-08-17
<fsssiedxa$"sssiedx 3.22 Low review 2026-08-17
%22fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.36 Low review 2026-08-14
&#x22;fsssiedxa&#x27;sssiedx 3.37 Low review 2026-08-14
fsssiedxa$"sssiedx 3.89 Low review 2026-08-14
<fsssiedxa$'sssiedx 3.54 Low review 2026-08-04
<fsssiedxa'sssiedx 3.39 Low review 2026-08-04
fsssiedxa<sssiedx 3.47 Low review 2026-08-04
fsssiedxa"sssiedx 3.35 Low review 2026-08-04
sssieddrubricxsx 3.73 Low review 2026-08-04
v3.6 2.68 Low review 2026-06-16
v3.4-rev 3.43 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA 2805879f8f83…
Force block — not fired
Score recovered no
Elapsed 27.1s