Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dark Mode for Shopify

hfoeimdgmlholdmiodhkeohhnjjkddhp
Risk Score
5.61
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 2,000
Rating 2.9
Last updated 2023-05-24 (37 months ago)
Manifest version MV3
CSP present ✅ yes
Developer tech@rvere.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy (not scoped to this extension) and admits data collection + third-party sharing — scored as worst-case.
  • Extension is 37 months stale (>36mo), maintenance pillar maxed at 10.0.
  • Brand impersonation: 'Shopify' named without confirmed owner affiliation; verified+featured discount applies but still +1.0.
  • Privacy policy admits data_collection=true AND third_party_sharing=true but scope_extension=false — generic Google policy with no extension scope.
  • Content scripts run on Shopify admin (authenticated merchant dashboard); any future supply-chain compromise has high-value target reach.

Evidence

  • privacy_policy_generic_google store Privacy URL points to Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
  • stale_37mo store Last updated May 2023; months_since_update=37 → maintenance pillar 10.0 + zombie booster not triggered (installs<10K).
  • brand_impersonation_shopify store brand_mention.is_impersonation=true, confirmed_owner=false; verified+featured → +1.0 Reputation per v3.2.
  • install_url_hijack crx install_url_hijack=true but install_url_target=null; cannot confirm 3rd-party target, scored conservatively as +2.0 Webstore.
  • monetization_google_analytics crx monetization_hits: google-analytics.com (telemetry tier) → +1.0 Webstore (telemetry-tier only).
  • dom_sink_innerhtml crx dom_sink_innerhtml_userctrl in popup.js; CSP present, no eval/CVE co-trigger → +0.5 Code Quality.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discount capped at -1.0 (v3.5E) due to monetization_hits non-empty.
  • no_developer_name store developer_name is empty string; +1.0 Reputation for no 'Offered by' name.

Permissions Breakdown

  • storage low Used to persist dark-mode preference locally; no exfil surface.
  • content_scripts: *.myshopify.com/admin*, accounts.shopify.com, admin.shopify.com medium Injects JS into Shopify admin pages; scoped but runs on authenticated merchant pages.

Pillar Scores

Permissions0.30
Reputation6.00
Network0.00
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA 486b5e84da4c…
Force block — not fired
Score recovered no
Elapsed 24.9s