Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Read Aloud: A Text to Speech Voice Reader

hdhinadidafjejdhmfkjgnolgimiaplp
Risk Score
2.00
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Accessibility
Installs 3,000,000
Rating 4.1
Last updated 2026-07-10 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@lsdsoftware.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • onedrive.live.com flagged as known-bad host (URLHaus malware_download/phishing) in js_external_hosts.
  • No content_security_policy; MV3 mitigates somewhat but broad external host list increases attack surface.
  • 12 external JS hosts including github.com, dropbox.com, stackoverflow.com — unusually broad for a TTS tool.
  • Privacy policy lacks retention disclosure and third-party sharing not explicitly addressed.
  • Developer name absent from listing; verified publisher status partially mitigates identity gap.

Evidence

  • known-bad-host api onedrive.live.com in js_external_hosts matches URLHaus malware_download/phishing entry in cve_findings_raw.
  • verified_publisher+featured store Extension holds verified publisher badge and is featured by Google, reducing reputation risk.
  • no_csp manifest content_security_policy is null; MV3 enforces strict defaults but no explicit CSP declared.
  • broad_external_hosts crx 12 distinct external hosts: assets.lsdsoftware.com, onedrive.live.com, dropbox.com, github.com, etc.
  • privacy_policy_retention_missing api Policy fetched, scoped, data_collection=true but retention=false and third_party_silence=true.
  • obfuscation_clean crx obfuscation_score=0.0; code_findings_raw empty; no eval/exfil indicators detected.
  • recently_updated store Last updated June 11 2026; months_since_update=0; maintenance risk minimal.
  • no_developer_name store developer_name is empty string; email support@lsdsoftware.com and domain resolves.

Permissions Breakdown

  • activeTab low Accesses current tab only on user action; scoped and low risk.
  • contextMenus low Adds right-click menu entry; no data access implied.
  • identity low No OAuth scopes declared; limited risk without broad scopes.
  • offscreen low MV3 offscreen document for audio processing; expected for TTS.
  • scripting medium Can inject scripts into pages, but paired only with activeTab not broad host.
  • storage low Local preference storage; standard low-risk permission.
  • tts low Core TTS playback API; expected for a text-to-speech extension.
  • ttsEngine low Registers a TTS engine; expected for this extension category.
  • https://translate.google.com/ low Narrow host permission to Google Translate only; justified for TTS translation.

Pillar Scores

Permissions2.00
Reputation2.00
Network3.50
Webstore2.00
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure2.00

Scoring History

xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 1.56 Low allow 2026-08-22
xx pfsssiedxa$"sssiedx 1.68 Low allow 2026-08-22
%22fsssiedxa$'sssiedx 1.65 Low allow 2026-08-22
&#x27;fsssiedxa"sssiedx 1.52 Low allow 2026-08-22
&#x27;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.05 Low allow 2026-08-22
&#x27;fsssiedxa$"sssiedx 1.66 Low allow 2026-08-22
&#x22;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 2.87 Low allow 2026-08-22
&#x22;fsssiedxa$'sssiedx 1.70 Low allow 2026-08-22
$"fsssiedxa sssiedx 1.52 Low allow 2026-08-22
fsssiedxa$"sssiedx 1.55 Low allow 2026-08-22
<fsssiedxa"sssiedx 1.49 Low allow 2026-08-22
<fsssiedxa&#x22;sssiedx 2.97 Low allow 2026-08-22
<fsssiedxa'sssiedx 2.87 Low allow 2026-08-22
<fsssiedxa$'sssiedx 2.85 Low allow 2026-08-22
<fsssiedxa xx psssiedx 1.55 Low allow 2026-08-22
<fsssiedxa&#x27;sssiedx 1.56 Low allow 2026-08-22
<fsssiedxa$"sssiedx 1.56 Low allow 2026-08-22
xx pfsssiedxa sssiedx 1.63 Low allow 2026-08-20
%22fsssiedxa$"sssiedx 1.50 Low allow 2026-08-20
&#x27;fsssiedxa'sssiedx 1.56 Low allow 2026-08-20
2.93 Low allow 2026-08-20
fsssiedxa<sssiedx 1.55 Low allow 2026-08-20
fsssiedxasssiedx 1.47 Low allow 2026-08-19
fsssiedxa"sssiedx 1.47 Low allow 2026-08-19
fsssiedxa 1.63 Low allow 2026-08-19
sssieddrubricxsx 2.87 Low allow 2026-08-19
v3.6 2.00 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA fb69f5ee8bb2…
Force block — not fired
Score recovered no
Elapsed 25.6s