Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

simple-modify-headers

gjgiipmpldkpbdfjkgofildhapegmmic
Risk Score
5.67
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 30,000
Rating 4.3
Last updated 2024-06-10 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer didierfred@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • declarativeNetRequestWithHostAccess + *://*/* allows modification/blocking of all HTTP requests across every site.
  • 26 months since last update — zombie extension with broad host access is high-risk acquisition target.
  • Privacy policy is Google's generic account policy (scope_extension=false, admits data collection and 3rd-party sharing): scores 10.
  • No CSP declared (MV3 default only) combined with innerHTML DOM-XSS sink in popup/config.js.
  • Free-webmail developer (gmail) with no verified publisher badge and generic non-scoped privacy policy.

Evidence

  • broad_host_access manifest host_permissions=[*://*/*] paired with declarativeNetRequestWithHostAccess — can intercept all requests.
  • stale_extension store Last updated June 2024; months_since_update=26. Abandoned/zombie risk.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • dom_xss_sink crx popup/config.js: innerHTML assigned from variable without sanitization; no CSP to mitigate.
  • no_csp manifest csp_present=false on MV3; default MV3 CSP applies but no explicit extension-level CSP hardening.
  • free_webmail_developer store Developer email didierfred@gmail.com; no verified publisher badge; no business domain.
  • featured_badge store is_featured_by_google=true; partial reputation credit applied.
  • no_cve_findings crx cve_findings_raw=[]; no known vulnerable bundled libraries detected.

Permissions Breakdown

  • activeTab low Grants access to active tab only on user gesture; limited scope.
  • tabs medium Can read tab URLs and metadata across all tabs.
  • storage low Local config storage; low standalone risk.
  • declarativeNetRequest medium Can modify/block network requests declaratively.
  • declarativeNetRequestWithHostAccess high HIGH: modifies requests on all hosts combined with *://*/* host permission.
  • *://*/* high Broad host access across all URLs; enables request interception on any site.

Pillar Scores

Permissions6.00
Reputation5.50
Network2.50
Webstore1.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-03 07:16
Listing SHA 6bbe46f22525…
Force block — not fired
Score recovered no
Elapsed