Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SplitPay – Payment Plan Builder

gmpbnbaadoblnejmacmdifimonhfahpo
Risk Score
4.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 13
Rating 5.0
Last updated 2026-04-30 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer saydiburkhon4@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • Developer uses free Gmail with no name or verified identity; no business accountability.
  • Backend is a developer-controlled Cloudflare Worker (splitpay-pro.saydiburkhon4.workers.dev) — opaque data sink.
  • No CSP on MV3 extension contacting external hosts; no code-level controls visible.
  • Extremely low install count (13) with no verifiable identity raises tail-attack-surface concern.

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • free_webmail_no_dev_name store developer_email=saydiburkhon4@gmail.com, developer_name empty; free-webmail + no identity → reputation floor 7.5.
  • developer_controlled_worker manifest host_permissions include splitpay-pro.saydiburkhon4.workers.dev — opaque Cloudflare Worker backend controlled by anonymous dev.
  • no_csp crx content_security_policy is null; MV3 has strict default but no explicit CSP declared.
  • network_external_hosts crx js_external_hosts: script.google.com, splitpay-pro.saydiburkhon4.workers.dev, splitpay-share.saydiburkhon4.workers.dev — 3 distinct domains.
  • no_bad_hosts_no_cves api bad_host_hits=[], cve_findings_raw=[], affiliate_hits=[], monetization_hits=[] — no active threat signals detected.
  • very_low_installs store Only 13 installs; rating=5 with no rating_count — insufficient signal for trust.
  • recently_updated store months_since_update=2; maintenance score 0.0.

Permissions Breakdown

  • storage low Local key-value store; no cross-origin read capability.
  • host: https://script.google.com/* medium Allows fetch to Google Apps Script; could exfil data via developer-controlled script.
  • host: https://splitpay-pro.saydiburkhon4.workers.dev/* medium Developer-controlled Cloudflare Worker; opaque backend with no accountability.

Pillar Scores

Permissions2.00
Reputation7.50
Network4.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA c7d23b75b05d…
Force block — not fired
Score recovered no
Elapsed 20.5s