Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

CSS validator

hhlcpmdhlcoghhfgiiopcjbkfmdliknc
Risk Score
5.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 417
Rating 4.0
Last updated 2024-11-19 (21 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@cssvalidator.app
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — does not scope to this extension; admits data collection and 3rd-party sharing (+10 privacy).
  • Uninstall URL hijack flagged (uninstall_url_hijack=true) and install URL hijack to cssvalidator.app/welcome — monetization/tracking risk.
  • No developer name listed; missing 'Offered by' accountability signal.
  • Extension stale 21 months (6-12mo band) with no changelog visible.
  • DOM-XSS sink (innerHTML from variable) in bundled ace.js with no CSP present.

Evidence

  • uninstall_url_hijack crx uninstall_url_hijack=true; install_url_hijack=true targeting https://cssvalidator.app/welcome — redirect tracking on lifecycle events.
  • generic_privacy_policy store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — generic and admits broad data sharing.
  • no_developer_name store developer_name is empty; no verified publisher badge; reduced accountability.
  • stale_extension store Last updated November 2024; months_since_update=21 — falls in 12-24mo band (+6.0 maintenance).
  • dom_xss_sink crx innerHTML assignment from variable in lib/ace/src/ace.js; no CSP present, elevating DOM-XSS risk.
  • external_hosts crx JS contacts cssvalidator.app, github.com, headlinegenerator.app — headlinegenerator.app is unrelated to CSS validation.
  • no_csp crx content_security_policy is null; csp_present=false for MV3 extension with DOM-sink finding.
  • install_url_hijack crx install_url_hijack=true; target https://cssvalidator.app/welcome — Webstore +2.0 per rule.

Permissions Breakdown

  • storage low Local key-value store only; no cross-origin data access.

Pillar Scores

Permissions0.80
Reputation6.50
Network0.00
Webstore6.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:43
Listing SHA 6e541bcd7963…
Force block — not fired
Score recovered no
Elapsed