Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Gantt Chart plugin: for GitLab

ggdacknafiabbfgekebgnhikdaonhmid
Risk Score
4.75
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 377
Rating 2.5
Last updated 2024-04-04 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer k402xxxcenxxx@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Developer uses free Gmail address (k402xxxcenxxx@gmail.com) with obfuscated-looking alias; no verified business identity.
  • Brand impersonation: mentions 'GitLab' but developer is not a confirmed GitLab owner and not a verified publisher.
  • Extension stale for 26 months with no updates; abandoned maintenance raises supply-chain risk.
  • Rating 2.5 (low) with no verified publisher or featured badge beyond is_featured_by_google.

Evidence

  • privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
  • brand_impersonation store brand_mention.is_impersonation=true for 'gitlab'; developer domain is gmail.com, confirmed_owner=false → +2.0 Reputation.
  • free_webmail_developer store Developer email k402xxxcenxxx@gmail.com; no business website; raises Reputation floor to 7.5.
  • stale_extension store last_updated April 4 2024; months_since_update=26 → Maintenance +8.5 (24-36mo band).
  • no_csp crx content_security_policy is null; MV3 so no +2.0 network penalty, but no CSP noted.
  • featured_by_google store is_featured_by_google=true; applies -2.0 Reputation discount (Featured badge).
  • content_scripts_scoped manifest Content scripts limited to https://*/*/*/-/milestones*; narrow GitLab-only scope matches stated function.
  • no_cve_findings crx cve_findings_raw empty; jquery 3.6.3 bundled has no flagged CVEs.

Permissions Breakdown

  • content_scripts: https://*/*/*/-/milestones* medium Scoped to GitLab milestone pages only; matches stated function, limited surface.

Pillar Scores

Permissions1.00
Reputation7.50
Network0.00
Webstore2.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA 530257a97abb…
Force block — not fired
Score recovered no
Elapsed 19.8s