Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Message Deleter for Slack 3.0

gpjmcgacbkeokgllnkjkiahiegkaalfb
Risk Score
5.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 4,000
Rating 3.7
Last updated 2023-07-31 (35 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@petasittek.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension name uses 'Slack' brand; developer not confirmed as Slack owner.
  • Near-zombie maintenance: 35 months since last update approaches >36mo critical threshold.
  • Privacy policy fetched but scope_extension==false and third_party_silence==true; coverage inadequate.
  • Install+uninstall URL hijack flags set; targets unspecified, indicating potential redirect behavior.
  • No developer name listed; anonymous publisher with only petasittek.com email identity.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'slack'; confirmed_owner=false; developer is petasittek.com.
  • install_uninstall_hijack manifest install_url_hijack=true AND uninstall_url_hijack=true; targets null but flags present in CRX.
  • maintenance_stale store Last updated July 31 2023; 35 months since update, near 36mo critical band.
  • privacy_policy_inadequate api Policy fetched; scope_extension=false, data_collection=false, third_party_silence=true -> +9.0+1.0.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit policy hardening.
  • no_developer_name store developer_name is empty string; +1.0 reputation penalty for anonymous publisher.
  • verified_publisher store verified_publisher=true but 0c cap applies: months_since_update=35>18mo caps discount to -1.0.
  • content_script_slack manifest content_scripts inject into https://app.slack.com/*; can access full Slack message DOM.

Permissions Breakdown

  • activeTab low Grants access to current tab only when user invokes extension; limited scope.
  • storage low Local key-value storage; no cross-site or sensitive data surface.
  • content_scripts: https://app.slack.com/* medium Injects JS into Slack; can read messages/DOM on that domain.

Pillar Scores

Permissions1.30
Reputation7.00
Network2.00
Webstore5.50
Maintenance8.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA 4aca37840a12…
Force block — not fired
Score recovered no
Elapsed 19.6s