Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Spotify Player+

haibeacocpobdaiimnfhjbkiggfacehc
Risk Score
5.42
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 6,000
Rating 3.9
Last updated 2022-01-12 (53 months ago)
Manifest version MV3
CSP present ✅ yes
Developer oliver@framecore.se
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Impersonates Spotify brand without confirmed ownership — is_impersonation=true.
  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — wholly inadequate for this extension.
  • Extension is abandoned: 53 months since last update (>36mo), zombie risk for any future compromise or sale.
  • Triple-stale fingerprint: >24mo stale + MV2-adjacent maintenance concern + Google generic policy.
  • No rating count available; rating 3.9 provides limited trust signal for 6K installs.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'spotify'; developer not confirmed_owner.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • abandoned_extension store Last updated January 2022; months_since_update=53 (>36mo maintenance floor).
  • developer_domain api framecore.se resolves, looks_throwaway=false; no verified publisher badge.
  • no_bad_hosts crx threat_intel bad_host_hits, affiliate_hits, monetization_hits all empty.
  • clean_code crx code_findings_raw empty, obfuscation_score=0.0, cve_findings_raw empty.
  • csp_present manifest CSP: script-src 'self'; object-src 'self' — strict, no remote script sources.
  • low_permissions manifest Only identity + storage declared; no host_permissions, no content_scripts.

Permissions Breakdown

  • identity low OAuth token access; scoped to Spotify auth flow, low standalone risk.
  • storage low Local extension storage only, no cross-origin data exposure.

Pillar Scores

Permissions0.60
Reputation7.00
Network0.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA 091fbd5d4e6e…
Force block — not fired
Score recovered no
Elapsed 19.4s