Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TankBillig.Info

hhfkhbefffgedhmmnccfjohojeoojpdh
Risk Score
4.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 141
Rating 3.7
Last updated 2026-06-11 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer chrome.webstore@willinger.cc
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy does not scope to this extension and omits third-party sharing detail (scope_extension=false).
  • No developer name listed; reduces accountability for geolocation data handling.
  • Install URL hijack opens tankbillig.info on install — minor but unsolicited navigation.
  • MV3 + no CSP declared; offscreen document use without CSP adds minor surface area.
  • Low install base (141) limits reputation signal; unverified publisher.

Evidence

  • privacy_policy_not_scoped api Policy fetched but scope_extension=false, data_collection=false, third_party_silence=true → +9.0 privacy.
  • no_developer_name store developer_name is empty string; no verified publisher badge → reputation starts at 5.0+1.0.
  • install_url_hijack manifest onInstalled opens https://tankbillig.info/ — unsolicited 3rd-party URL open on install.
  • geolocation_permission manifest Requests geolocation; appropriate for fuel-price finder but sensitive without retention disclosure.
  • csp_absent_mv3 manifest content_security_policy is null; MV3 default CSP applies so no network penalty, but offscreen use noted.
  • no_bad_hosts_no_cves api threat_intel bad_host_hits=[], affiliate_hits=[], cve_findings_raw=[] — clean threat intel.
  • low_installs_unverified store 141 installs, no verified publisher, no featured badge — limited trust signal.
  • code_clean crx obfuscation_score=0.0, code_findings_raw=[], 4 JS files scanned — no malicious indicators found.

Permissions Breakdown

  • geolocation medium Accesses user physical location; reasonable for a fuel-price finder but sensitive data.
  • storage low Local data persistence only; low standalone risk.
  • offscreen low Allows off-screen document; slightly unusual but no high-impact capability declared.

Pillar Scores

Permissions1.30
Reputation6.00
Network0.00
Webstore2.00
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-15 14:22
Listing SHA 1911e947ad22…
Force block — not fired
Score recovered no
Elapsed