Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Словарёк

himipdblnokdafogmdlmajgokiopcbjk
Risk Score
4.48
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 1,000
Rating 5.0
Last updated 2026-04-30 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer robertblind91@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host_permissions (http://*/* + https://*/*) with scripting allow injection into every page; no CSP.
  • Privacy policy has length=21 (effectively empty), not scoped to extension, third-party silence.
  • Free-webmail dev (gmail), no developer name — anonymous publisher with broad reach.
  • Uninstall URL hijack flag set — extension registers an uninstall redirect to unknown third-party URL.
  • External JS host vuejs.org contacted; no CSP on MV3 extension using scripting + broad hosts.

Evidence

  • broad_host_permissions manifest host_permissions include http://*/* and https://*/*, enabling scripting injection on all sites.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target null but hijack flag present, indicating 3rd-party redirect on removal.
  • privacy_policy_inadequate api Policy length=21 chars, scope_extension=false, data_collection=false, third_party_silence=true.
  • anonymous_developer store developer_name empty; email robertblind91@gmail.com (free webmail); no business identity.
  • external_js_host crx js_external_hosts: api.slovarek.hrprime.ru and vuejs.org contacted; no CSP to restrict.
  • no_csp manifest content_security_policy null; csp_present=false on MV3 extension with broad hosts and scripting.
  • verified_publisher_gmail store verified_publisher=true but email is free gmail; no developer domain resolved or confirmed.
  • geo_diversity api JS hosts span CA and RU (country_count=2); hrprime.ru is .ru TLD with Russian-hosted API.

Permissions Breakdown

  • scripting medium Can inject JS into any page given broad host permissions.
  • storage low Local storage only; low inherent risk.
  • http://*/* high Broad host access across all HTTP sites.
  • https://*/* high Broad host access across all HTTPS sites.

Pillar Scores

Permissions5.50
Reputation6.50
Network4.00
Webstore3.50
Maintenance1.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:43
Listing SHA 7dd2d8d9dd9d…
Force block — not fired
Score recovered no
Elapsed