Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ghgabhipcejejjmhhchfonmamedcbeod

ghgabhipcejejjmhhchfonmamedcbeod
Risk Score
3.68
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category PrivacyTool
Installs
Rating
Last updated
Manifest version MV?
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Web Store open ↗

Top Risks

  • Broad host access (http/https all URLs) combined with cookies and browsingData enables full session and history access.
  • Uninstall URL hijack detected; redirects user after removal to a third-party destination.
  • Privacy policy confirms data collection and third-party sharing but lacks retention disclosure.
  • last_updated unknown — maintenance risk cannot be fully assessed; 6+ months stale assumed.
  • CSP connect-src includes api64.com and appn.center (non-dev domains); adds external trust surface.

Evidence

  • broad_host_permissions manifest host_permissions include http://*/* and https://*/* paired with cookies and browsingData.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target unspecified but triggers post-removal redirect.
  • verified_publisher_featured store Extension has verified publisher badge and is featured by Google; strong trust signal.
  • privacy_policy_third_party_sharing api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • external_csp_hosts manifest CSP connect-src includes api64.com and appn.center outside developer-controlled domain.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; no malicious code indicators detected.
  • maintenance_unknown store last_updated is null; cannot confirm recency — defaulting to 6-12 months stale band.
  • operator_cluster_dev_email api sibling_count=0 compound; dev_email dimension shows 2 — one sibling extension under same email.

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata; moderate risk for a privacy-cleaning tool.
  • browsingData high Can delete history, cookies, cache across all sites; core function but powerful.
  • history high Full read/write access to browsing history; broad data access.
  • cookies high Read/delete cookies across all origins; paired with broad host access.
  • scripting medium Can inject scripts; scope limited by host_permissions.
  • storage low Local extension storage; standard and low risk.
  • contextMenus low Adds right-click menu items; minimal risk.
  • http://*/* high Broad host access over HTTP; combined with cookies amplifies risk.
  • https://*/* high Broad host access over HTTPS; combined with cookies amplifies risk.

Pillar Scores

Permissions4.50
Reputation2.00
Network3.50
Webstore4.00
Maintenance6.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Scoring History

xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.14 Low review 2026-08-09
"fsssiedxasssiedx 3.09 Low review 2026-08-09
'fsssiedxasssiedx 3.17 Low review 2026-08-09
&#x27;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.04 Low review 2026-08-09
&#x22;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.54 Low review 2026-08-09
fsssiedxa<sssiedx 3.05 Low review 2026-08-09
v3.69490"();}]9524 3.57 Low review 2026-08-05
dfb{{98991*97996}}xca 2.91 Low review 2026-08-05
v3.6&n993967=v939252 2.18 Low review 2026-08-05
%76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%71%56%76%45%28%39%38%34%34%34%29%22 4.04 Medium review 2026-08-04
<th:t="${dfb}#foreach 3.40 Low review 2026-08-04
v3.6&n913079=v980432 3.29 Low review 2026-08-04
fsssiedxa"sssiedx 3.02 Low review 2026-08-03
fsssiedxa 2.82 Low review 2026-08-03
sssieddrubricxsx 3.01 Low review 2026-08-03
v3.6</script><script>7AjZ(9425)</script> 2.92 Low review 2026-07-29
%F6"onmouseover=7AjZ(94585)// 3.48 Low review 2026-07-29
dfb__${98991*97996}__::.x 3.02 Low review 2026-07-29
<%={{={@{#{${dfb}}%> 3.17 Low review 2026-07-29
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 3.13 Low review 2026-07-29
v3.69304079< 3.14 Low review 2026-07-29
v3.6'"()&%<zzz><ScRiPt >7AjZ(9220)</ScRiPt> 3.07 Low review 2026-07-29
v3.6&n919386=v984373 2.92 Low review 2026-07-29
v3.6 3.68 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA 14a4ff5b4e55…
Force block — not fired
Score recovered no
Elapsed 22.0s