Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shopify Product Info by OptimCommerce

hgdnbhdgboglidilhoipggepjlmmmaae
Risk Score
4.37
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 3,000
Rating 5.0
Last updated 2025-03-09 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer hovomk@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed (HTTPError); policy adequacy cannot be confirmed, scored as unfetched.
  • Brand impersonation: mentions 'Shopify' but developer is unverified gmail user with no confirmed ownership.
  • Content script declared on https://*/* runs on all HTTPS sites, far broader than Shopify-only stated function.
  • Developer uses free webmail (gmail) with no developer name listed; identity unverifiable.
  • DOM-XSS sink (innerHTML) with no CSP present; stored/reflected data from page could be unsafe.

Evidence

  • privacy_policy_fetch_failed api Privacy policy URL returned HTTPError; fetched==false → scored +10.0 on privacy pillar.
  • brand_impersonation store brand_mention.is_impersonation==true for 'shopify'; developer is gmail user, confirmed_owner==false.
  • broad_content_script manifest content_scripts_matches=['https://*/*'] — all HTTPS sites, but stated purpose is Shopify only.
  • free_webmail_no_dev_name store developer_email=hovomk@gmail.com; developer_name is empty; identity unverifiable.
  • dom_xss_sink_no_csp crx innerHTML assigned from variable in popup.js; csp_present==false increases XSS risk.
  • verified_publisher_featured store verified_publisher==true AND is_featured_by_google==true; partially mitigates reputation risk.
  • maintenance_stale store months_since_update=15; falls in 12-24mo band → +6.0 maintenance score.
  • no_bad_hosts_no_cves crx bad_host_hits, affiliate_hits, monetization_hits all empty; cve_findings_raw empty.

Permissions Breakdown

  • activeTab low Grants access only to the currently active tab on user action; low passive risk.
  • scripting medium Allows script injection into pages; paired with activeTab limits scope but still enables DOM manipulation.
  • content_scripts https://*/* medium Content script runs on all HTTPS pages, broad reach beyond stated Shopify-only purpose.

Pillar Scores

Permissions2.30
Reputation5.50
Network0.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA e19f43588db9…
Force block — not fired
Score recovered no
Elapsed 21.9s