Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Twitter Extras

hapodabojpphnloafpaapmcpofcbanaj
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 521
Rating 5.0
Last updated 2024-05-24 (25 months ago)
Manifest version MV3
CSP present ❌ no
Developer jjdsampson@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing (+10.0 privacy).
  • Brand impersonation: 'Twitter' in name, unverified gmail developer, no business identity (+2.0 reputation).
  • Extension is 25 months stale — no update since May 2024 (+8.5 maintenance).
  • Free-webmail developer with no name or business domain; zero accountability chain (+1.5 reputation).
  • Verified-publisher discount capped at -1.0 due to staleness >18mo (v3.5 invariant 0c).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=['twitter'], confirmed_owner=false, dev domain is gmail.com.
  • generic_privacy_policy store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • stale_extension store months_since_update=25; falls in 24-36mo band (+8.5 maintenance).
  • free_webmail_dev_no_name manifest developer_email=jjdsampson@gmail.com, developer_name=''; no business website or verified identity.
  • no_csp crx content_security_policy=null; MV3 default applies but no explicit policy declared.
  • no_code_findings crx code_findings_raw=[], obfuscation_score=0.0; no malicious code patterns detected.
  • no_threat_intel_hits api bad_host_hits=[], affiliate_hits=[], monetization_hits=[]; only external JS host is x.com.
  • verified_publisher store verified_publisher=true; however, 0c cap applies: months_since_update=25 >18mo caps discount to -1.0.

Permissions Breakdown

  • downloads medium Allows saving files to disk; consistent with video-download function.
  • scripting medium Can inject scripts into pages; scoped here to x.com/* only.
  • storage low Local preference storage; low standalone risk.
  • https://x.com/* medium Host permission scoped to x.com only; narrows blast radius.

Pillar Scores

Permissions2.50
Reputation7.50
Network2.00
Webstore3.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA fb8ee09dbf07…
Force block — not fired
Score recovered no
Elapsed 23.7s