Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

NFT to silly jpeg

hcajgiblhhpbgbmlgioljefhmoolebjn
Risk Score
6.04
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Other
Installs 121
Rating 4.8
Last updated 2022-01-28 (53 months ago)
Manifest version MV3
CSP present ❌ no
Developer hi@corsa-labs.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope to this extension; classified as collecting and sharing data with third parties.
  • Extension last updated January 2022 (53 months); abandoned with broad host access is a supply-chain acquisition risk.
  • Broad host_permissions *://*/* + content_scripts on all URLs gives full DOM access to every page.
  • No CSP declared; MV3 provides some default protections but no explicit policy increases attack surface.
  • Small install count (121) with HIGH-tier permissions flagged as tail-attack-surface anomaly.

Evidence

  • broad_host_permissions manifest host_permissions and content_scripts_matches both set to *://*/* — runs on every site.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • stale_extension store Last updated January 2022, 53 months ago. No updates since release.
  • no_csp manifest content_security_policy is null; no explicit CSP declared.
  • install_perm_anomaly api 121 installs with high-tier host permission; tail_attack_surface=true, small_install_high_perm=true.
  • external_host_is_gd crx js_external_hosts contains is.gd (URL shortener) — unclear why a text-replacement extension contacts this.
  • featured_by_google store is_featured_by_google=true; provides mild reputation credit but does not override stale/policy concerns.
  • no_bad_hosts_no_cves crx cve_findings_raw and bad_host_hits both empty; code_findings_raw empty; obfuscation_score=0.

Permissions Breakdown

  • host_permissions: *://*/* high Broad host access allows content script injection on every site the user visits.
  • content_scripts_matches: *://*/* high Content script runs on all URLs; combined with broad host perms, full DOM read/write everywhere.

Pillar Scores

Permissions5.50
Reputation4.50
Network2.00
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA 0650e90ce92e…
Force block — not fired
Score recovered no
Elapsed 19.0s