Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

360 Internet Protection

glcimepnljoholdmjchkloafkggfoijh
Risk Score
4.44
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 17,000,000
Rating 4.5
Last updated 2025-12-12 (8 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@360safe.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • nativeMessaging with unrecognized publisher companion app exposes OS-level attack surface.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
  • webRequest + declarativeNetRequestWithHostAccess + <all_urls>: full traffic interception capability.
  • Contacts DoubleClick (ad network) and Google Analytics — telemetry/monetization on a security tool.
  • 18M installs amplify blast radius of any future supply-chain compromise or developer account takeover.

Evidence

  • nativeMessaging_unrecognized_publisher crx native_messaging_check: has_native_messaging=true, publisher_recognized=false; +3.0 Permissions.
  • privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5-D).
  • monetization_hits_security_category api stats.g.doubleclick.net (Google ads) + google-analytics in threat_intel.monetization_hits; +1.0 Webstore (telemetry tier).
  • geo_diversity_high api JS hosts span 5 countries (IN/NL/SG/TH/US); category=Security qualifies for geo exemption — no penalty applied.
  • verified_publisher store verified_publisher=true; monetization_hits non-empty → invariant 0c caps discount at -1.0 (not -3.0).
  • broad_host_permissions manifest <all_urls> + content_scripts on http://* https://*; justified-broad discount applied for Security category.
  • no_code_findings crx code_findings_raw=[], obfuscation_score=0.0; code quality pillar = 0.00.
  • recently_updated store Last updated December 2025 (~1 month ago); maintenance score = 0.00.

Permissions Breakdown

  • scripting medium Can inject scripts into pages; medium risk but paired with <all_urls> raises concern.
  • tabs medium Access to tab URLs and metadata across all tabs.
  • nativeMessaging high Communicates with native host app; publisher_recognized=false per native_messaging_check.
  • storage low Local extension storage, standard use.
  • activeTab low Scoped to user-initiated interaction.
  • webRequest high Can observe all HTTP requests; high capability for a security tool with <all_urls>.
  • webNavigation medium Monitors navigation events across all sites.
  • declarativeNetRequestWithHostAccess high Declarative network blocking/redirecting on all URLs; broad host access multiplier applies.
  • alarms low Periodic background tasks only.
  • <all_urls> (host_permission) high Full access to every URL visited; content scripts on http://* and https://* confirm breadth.

Pillar Scores

Permissions6.50
Reputation3.00
Network3.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

"fsssiedxa$'sssiedx 4.98 Medium review 2026-08-15
&#x27;fsssiedxa$'sssiedx 5.41 Medium review 2026-08-15
fsssiedxa<sssiedx 4.96 Medium review 2026-08-15
<fsssiedxa'sssiedx 4.69 Medium review 2026-08-09
<fsssiedxi sssiedx 5.09 Medium review 2026-08-09
fsssiedx<sssiedx 5.01 Medium review 2026-08-09
%F6"onmouseover=OFWU(93865)// 5.45 Medium review 2026-08-05
<th:t="${dfb}#foreach 5.13 Medium review 2026-08-05
v3.6&n954881=v997810 4.12 Medium review 2026-08-05
sssieddrubricxsx 5.21 Medium review 2026-07-31
v3.69334"();}]9428 4.77 Medium review 2026-07-29
v3.6"><script>6PoI(9756)</script> 5.27 Medium review 2026-07-29
v3.6" pYO5=6PoI([!+!]) TXz=" 5.14 Medium review 2026-07-29
v3.6"onmouseover=6PoI(90212)" 5.01 Medium review 2026-07-29
<%={{={@{#{${dfb}}%> 4.55 Medium review 2026-07-29
v3.69656337 4.71 Medium review 2026-07-29
v3.6'"()&%<zzz><ScRiPt >6PoI(9032)</ScRiPt> 4.56 Medium review 2026-07-29
v3.6 4.44 Medium review 2026-06-15
v3.4-rev 4.48 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 14:14
Listing SHA 8a07455a363b…
Force block — not fired
Score recovered no
Elapsed 27.0s