Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Better Color Picker - pick any color in Chrome

gpibachbddnihfkbjcfggbejjgjdijeb
Risk Score
4.42
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 5,000
Rating 4.7
Last updated 2026-08-18
Manifest version MV3
CSP present ❌ no
Developer kauffman.be72@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy hosted on freeprivacypolicy.com: not scoped to this extension, admits data collection and third-party sharing — worst-case generic policy.
  • Uninstall URL hijack detected (target null but flag set); classic monetization/tracking signal.
  • Broad host permissions (http://*/*, https://*/*) with content scripts on all sites; colour picker function doesn't require this reach.
  • Free-webmail developer (gmail.com) with no verified publisher badge; no business website or domain identity.
  • External JS host 'better-color-picker.guru' contacted; unverified domain could be a future supply-chain vector.

Evidence

  • uninstall_url_hijack crx uninstall_url_hijack=true; +3.0 Webstore per rubric for 3rd-party uninstall URL.
  • privacy_policy_generic_with_collection_and_sharing api freeprivacypolicy.com policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5-D).
  • broad_host_permissions manifest host_permissions=[http://*/*, https://*/*] + content_scripts on all URLs; colour picker does not justify this.
  • free_webmail_developer store Developer email kauffman.be72@gmail.com; numbered alias pattern (be72); no verified publisher.
  • external_js_host crx js_external_hosts=[better-color-picker.guru]; single external domain, no bad-host hit but unverified.
  • no_csp manifest csp_present=false on MV3; no additional MV2 penalty but CSP absent increases injection surface.
  • operator_cluster_singleton api sibling_count=0; no cluster amplifier applied.
  • cve_findings_empty crx No CVEs detected; cve_pillar_score=0.0.

Permissions Breakdown

  • storage low Stores user preferences locally; low impact.
  • declarativeNetRequest medium Can block/modify network requests; medium risk without webRequestBlocking.
  • http://*/* high Broad host access across all HTTP sites; content scripts run everywhere.
  • https://*/* high Broad host access across all HTTPS sites; content scripts run everywhere.

Pillar Scores

Permissions5.00
Reputation6.50
Network3.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:09
Listing SHA f88e0120b622…
Force block — not fired
Score recovered no
Elapsed