Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

FullPage Capture - Full Page Screenshot

ggacghlcchiiejclfdajbpkbjfgjhfol
Risk Score
3.55
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Screenshot
Installs 100,000
Rating 4.8
Last updated 2026-08-27
Manifest version MV3
CSP present ❌ no
Developer maggiore55ferrari@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail) with no developer name; verified badge exists but identity weak.
  • Uninstall and install URL hijacks flagged — extension intercepts lifecycle events.
  • description_promise mismatch: claims recording capability but lacks tabCapture/desktopCapture.
  • <all_urls> host permission + scripting enables JS injection on every site user visits.
  • Privacy policy admits third-party data sharing; no retention period disclosed.

Evidence

  • install_url_hijack + uninstall_url_hijack crx Both install and uninstall URL hooks present; targets not resolvable — lifecycle tracking risk.
  • developer_email free-webmail, no developer_name store maggiore55ferrari@gmail.com with empty developer_name; verified_publisher=true partially offsets.
  • description_promise mismatch store Extension promises recording but declares neither tabCapture nor desktopCapture permissions.
  • privacy_policy third_party_sharing=true, retention=false api Policy scoped to extension and admits data collection + 3rd-party sharing; no retention stated.
  • js_external_hosts includes ntp.msn.com crx MSN NTP endpoint contacted alongside chrome/edge stores; unusual for screenshot tool.
  • csp_present=false on MV3 manifest No explicit CSP declared; MV3 default applies but no explicit scoping present.
  • verified_publisher + is_featured_by_google store Both badges present, partially mitigating reputation risk despite gmail identity.
  • code_findings_raw empty, obfuscation_score=0.0 crx 18 JS files scanned; no malicious patterns or obfuscation detected.

Permissions Breakdown

  • activeTab medium Grants access to current tab on user action; scoped but still captures tab content.
  • scripting high Allows programmatic JS injection into pages; paired with <all_urls> host permission.
  • storage low Local key-value storage only; standard for extension state.
  • unlimitedStorage low Removes storage quota cap; reasonable for screenshot extension storing captures.
  • webNavigation medium Observes navigation events across tabs; wider than strictly needed for screenshots.
  • contextMenus low Adds right-click menu items; low-risk UI integration.
  • <all_urls> high Host permission covering all sites; required for full-page capture but maximises reach.

Pillar Scores

Permissions5.50
Reputation5.50
Network3.00
Webstore5.50
Maintenance0.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:51
Listing SHA 075bee78a4a1…
Force block — not fired
Score recovered no
Elapsed