Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Webpage Word Counter

hjncbnemkcdjfobfcdlbhkeahldjobhm
Risk Score
3.58
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 6,000
Rating 4.1
Last updated 2026-01-05 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer zhaoyy0666@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own generic policy — not scoped to this extension at all; admits data collection and third-party sharing.
  • Developer uses a free Gmail address with no name or verified business identity.
  • No CSP on MV3 extension; scripting permission could inject arbitrary JS into active tab.
  • Low install base (6k) with anonymous developer reduces accountability.
  • Featured badge provides limited trust when developer identity is unverifiable.

Evidence

  • privacy_policy_generic store PP URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension. scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_identity store developer_name is empty; developer_email is zhaoyy0666@gmail.com — free webmail, no business identity.
  • featured_badge store is_featured_by_google=true provides some positive signal but does not compensate for absent privacy policy.
  • permissions_scope manifest Only activeTab + scripting declared; no host_permissions or broad URL patterns — minimal capability surface.
  • code_clean crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — no malicious indicators found.
  • threat_intel_clean api bad_host_hits, affiliate_hits, monetization_hits all empty; no bad network destinations.
  • maintenance_recent store Last updated January 5, 2026; months_since_update=5 — actively maintained.
  • cve_none crx cve_findings_raw empty; no vulnerable bundled libraries detected.

Permissions Breakdown

  • activeTab low Grants access to current tab only on user action; limited scope.
  • scripting medium Allows injecting scripts into pages; medium risk, paired only with activeTab.

Pillar Scores

Permissions1.30
Reputation6.50
Network2.00
Webstore0.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA a07ab9c5b224…
Force block — not fired
Score recovered no
Elapsed 17.8s