Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Spotify player

gokeibibpoonnkpojbkknfnjgojdjlhm
Risk Score
5.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 3,000
Rating 1.7
Last updated 2024-09-17 (21 months ago)
Manifest version MV3
CSP present ✅ yes
Developer help.nextgensoultions@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Spotify brand impersonation by unverified gmail developer — high risk of credential harvesting or account abuse.
  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — +10.0 privacy pillar.
  • Low rating (1.7) on a Spotify-named extension with gmail dev email signals potential abuse.
  • Unknown host superwhomp.com in js_external_hosts — unrecognized third-party endpoint with no explanation.
  • Stale extension (21 months since update) with brand impersonation and no verified publisher accountability.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'spotify'; developer is unverified gmail account, not Spotify AB.
  • free_webmail_developer store Developer email help.nextgensoultions@gmail.com — gmail with no verified business domain.
  • generic_privacy_policy store Privacy policy is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • unknown_external_host crx js_external_hosts includes superwhomp.com — unrecognized domain, no threat_intel hit but unexplained.
  • low_rating store Rating 1.7 — very low; insufficient rating_count data but signal is negative.
  • stale_extension store Last updated September 2024; months_since_update=21, in 6-12mo maintenance band.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false — no accountability signals.
  • cve_findings crx cve_findings_raw empty; no CVE exposure detected.

Permissions Breakdown

  • storage low Stores local extension state; minimal risk.
  • identity low Used for OAuth token acquisition; scoped to Spotify auth flow.
  • https://api.spotify.com/* medium Host permission to Spotify API; enables reading/controlling user Spotify account.
  • https://accounts.spotify.com/* medium Host permission for Spotify auth; required for OAuth but grants auth-page access.

Pillar Scores

Permissions1.30
Reputation8.50
Network2.00
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA 4efef9904a11…
Force block — not fired
Score recovered no
Elapsed 19.7s