Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Youtube ad fast-forwarder

gimgmkmpmjfjdnlmolehpabbehcflhpc
Risk Score
4.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Adblock
Installs 3,000
Rating 4.3
Last updated 2025-04-25 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer solehruziboev@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope or describe this extension's data practices.
  • Brand impersonation: 'YouTube' in name, developer is unaffiliated gmail user with no verified business.
  • Extension contacts youtube-skip-ads-please-oregon.onrender.com — unverified third-party backend on free hosting.
  • Maintenance lag: 14 months since last update places extension in 6–24mo stale band.
  • Free-webmail developer (gmail), no verified publisher badge, no business domain — low accountability.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; 'YouTube' brand used, confirmed_owner=false, dev domain is gmail.com.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • third_party_backend crx js_external_hosts includes youtube-skip-ads-please-oregon.onrender.com — free-tier Render.com host, unknown owner.
  • free_webmail_developer store developer_email=solehruziboev@gmail.com; no business website; domain_age_ct not queried (free_webmail).
  • featured_by_google store is_featured_by_google=true; partial reputation mitigation applied.
  • maintenance_stale store months_since_update=14; falls in 6–24mo band → +6.0 maintenance score.
  • no_csp manifest content_security_policy=null on MV3; MV3 has strict default so no v2 +2.0 network penalty applied.
  • no_code_findings crx code_findings_raw=[], obfuscation_score=0.0; no malicious code signals detected.

Permissions Breakdown

  • tabs medium Can read tab URLs/titles; combined with content scripts adds moderate surveillance surface.
  • storage low Local preference persistence only; no exfil risk on its own.
  • https://www.youtube.com/* medium Host access scoped to YouTube only; content scripts can read/modify YouTube page DOM.

Pillar Scores

Permissions1.30
Reputation7.50
Network2.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA 8351da1ad1b9…
Force block — not fired
Score recovered no
Elapsed 20.6s