Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

LastPass: Free Password Manager

hdokiejnpimakedhajhdlcegeplioahd
Risk Score
3.68
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Security
Installs 8,000,000
Rating 4.2
Last updated 2026-08-26
Manifest version MV3
CSP present ✅ yes
Developer extension-store@lastpass.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true: Privacy pillar scores 10.0.
  • Broad host access (http://*/* + https://*/*) combined with cookies and webRequest enables full page and credential interception.
  • Dynamic script injection (script_src_dynamic) and innerHTML sinks in React bundle introduce DOM-XSS surface across all visited pages.
  • CSP connect-src is very broad, covering multiple IdP/SSO domains, DataDog telemetry, and pwnedpasswords.com.
  • LastPass has a significant public breach history (2022); high-value credential-manager target warrants elevated scrutiny.

Evidence

  • privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic policy admits sharing without extension scope.
  • broad_host_access manifest host_permissions http://*/* + https://*/* with content_scripts on same; justified for password manager autofill.
  • featured_by_google store is_featured_by_google=true; applies -1.5 reputation discount (featured badge).
  • no_verified_publisher store verified_publisher=false; no -3.0 reputation discount applied.
  • script_src_dynamic crx Webpack runtime creates dynamic <script> elements; common in SPA bundles but raises code-quality score.
  • dom_sink_innerhtml crx Two innerHTML sinks in React and federated-login bundles; CSP present limits exploitation but not eliminated.
  • cve_findings_empty crx No CVEs found in bundled libraries despite jquery 3.6.0 and react 16.13.1 being present.
  • threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain lastpass.com resolves and not throwaway.

Permissions Breakdown

  • scripting high Can inject JS into any page; core to password manager but high capability.
  • tabs medium Access to tab URLs and metadata across all tabs.
  • notifications low Can display system notifications; low direct data risk.
  • contextMenus low Adds right-click menu items; minimal risk.
  • storage low Local extension storage; expected for password manager.
  • unlimitedStorage low Removes storage quota; expected for vault data.
  • webNavigation medium Observes navigation events across all pages; needed for autofill triggers.
  • webRequest high Can observe all HTTP requests; broad surveillance capability.
  • webRequestAuthProvider high Can intercept HTTP auth challenges; elevated credential-handling risk.
  • offscreen low Background document for audio/DOM tasks; low risk in context.
  • alarms low Scheduled background tasks; minimal risk.
  • cookies high Read/write cookies across all origins; high risk paired with broad host access.
  • http://*/* high Content script on all HTTP pages; necessary for autofill but very broad.
  • https://*/* high Content script on all HTTPS pages; necessary for autofill but very broad.

Pillar Scores

Permissions5.50
Reputation2.50
Network2.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure0.00

Scoring History

sssiedn5393d766dp727562726963xsx 3.66 Low review 2026-08-30
&#x27;fsssiedxa sssiedx 4.17 Medium review 2026-08-20
fsssiedxa$"sssiedx 3.87 Low review 2026-08-20
v3.6"onmouseover=XJX5(97492)" 4.29 Medium review 2026-08-05
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 4.39 Medium review 2026-08-05
v3.6&n979076=v974800 4.14 Medium review 2026-08-05
%76%33%2E%36%39%32%37%33%22%28%29%3B%7D%5D%39%32%34%33 2.81 Low review 2026-08-04
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 4.07 Medium review 2026-08-04
v3.6&n940129=v912328 4.10 Medium review 2026-08-04
%F6"onmouseover=5qLv(95245)// 4.54 Medium review 2026-07-29
dfb{{98991*97996}}xca 5.01 Medium review 2026-07-29
<th:t="${dfb}#foreach 4.41 Medium review 2026-07-29
v3.6&n945879=v954514 4.55 Medium review 2026-07-29
%27fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.08 Medium review 2026-07-28
fsssiedxa<sssiedx 4.17 Medium review 2026-07-28
fsssiedxa'sssiedx 3.86 Low review 2026-07-28
sssieddrubricxsx 2.86 Low review 2026-07-28
v3.6 3.68 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA 03a9250501a9…
Force block — not fired
Score recovered no
Elapsed 33.4s