Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Search G. Calendar Tasks (By Natfluence)

hbbihbhfopbfekplgcaoaacnhpjdkbdf
Risk Score
4.52
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 2,000
Rating 3.8
Last updated 2025-01-27 (17 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@natfluence.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returned HTTP error (fetch_error) — policy content unverifiable; privacy pillar scores maximum.
  • Brand impersonation: 'google' mentioned in title/name but developer is not a confirmed Google owner.
  • No CSP declared (MV3 popup) and innerHTML DOM-XSS sink found in popup.js.
  • identity + identity.email permissions allow OAuth token acquisition and email read — significant if extension is ever compromised.
  • Months since update = 17; approaching stale threshold with unresolved privacy policy fetch failure.

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (fetch_error:HTTPError); privacy pillar capped at 10.0.
  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[google]; confirmed_owner=false; verified_publisher=true → +1.0.
  • dom_xss_sink crx popup.js: innerHTML assigned from variable; no CSP present → dom_sink_innerhtml_userctrl scores +2.0 (FIX B).
  • no_csp manifest content_security_policy=null; MV3 has strict default but no explicit CSP declared.
  • identity_permissions manifest identity + identity.email grant OAuth token and email address access to Google services.
  • external_js_hosts crx js_external_hosts: dexie.org, fontawesome.com, tinyurl.com, www.apache.org — 4 distinct domains, country_count=2.
  • maintenance_stale store months_since_update=17; scores +6.0 (6-12mo band exceeded; 17mo = 12-24mo band).
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; partial reputation discount applied.

Permissions Breakdown

  • alarms low Schedules background tasks; minimal privacy risk.
  • identity medium OAuth token access; can authenticate as user against Google APIs.
  • identity.email medium Reads the signed-in user's email address via identity API.
  • storage low Local extension storage only.
  • unlimitedStorage low Allows larger local storage quota; no network risk on its own.

Pillar Scores

Permissions2.30
Reputation4.50
Network3.50
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA c5cc53644526…
Force block — not fired
Score recovered no
Elapsed 23.9s