Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Cookie-Editor

hlkenndednhfkekhgcdicdfddnkalmdm
Risk Score
4.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 2,000,000
Rating 4.4
Last updated 2024-02-25 (30 months ago)
Manifest version MV3
CSP present ❌ no
Developer christopheextensions@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies permission grants full read/write access to all browser cookies across all sites.
  • Developer uses free Gmail address with no verified business identity; no developer name listed.
  • 28 months since last update — stale for a 2M-install extension.
  • Privacy policy fetched but scope_extension=false and does not confirm data_collection=false explicitly for this extension; third_party_silence=true adds uncertainty.
  • 11 external JS hosts referenced (affiliate/sponsor links visible); no CSP on MV3 — network surface broader than expected.

Evidence

  • cookies_permission manifest cookies permission declared with no host_permissions — applies to all domains accessible to the browser.
  • free_webmail_dev store Developer email christopheextensions@gmail.com; developer_name empty; no verified publisher badge.
  • stale_extension store Last updated February 2024, 28 months ago; 2M installs creates large attack surface if compromised.
  • privacy_policy_scope api Policy fetched (879 chars) but scope_extension=false; data_collection=false, retention=false, third_party_silence=true.
  • external_hosts crx 11 external hosts including aurainc.sjv.io, skillshare.eqcm.net, namecheap.pxf.io — affiliate/sponsor link domains.
  • geo_diversity api JS hosts span 4 countries (CA, IE, IN, US); triggers +1.5 network penalty for DeveloperTools category.
  • no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty — clean code scan.
  • verified_publisher store verified_publisher=true but months_since_update=28 >18mo triggers invariant 0c; discount capped at -1.0.

Permissions Breakdown

  • cookies high Full read/write access to all browser cookies; core to stated function but high abuse potential.
  • tabs medium Access to tab URLs and metadata; needed to scope cookie editing to active tab.
  • storage low Local extension storage for preferences; low inherent risk.
  • sidePanel low Displays extension UI in side panel; no data access.

Pillar Scores

Permissions4.50
Reputation6.50
Network3.50
Webstore3.00
Maintenance6.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Scoring History

v3.6" U9F4=4SiS([!+!]) dK8=" 4.79 Medium review 2026-08-05
dfb[[${98991*97996}]]xca 4.86 Medium review 2026-08-05
v3.6&n903072=v943206 4.88 Medium review 2026-08-05
v3.6</script><script>dkHI(9914)</script> 5.02 Medium review 2026-07-29
%76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%64%6B%48%49%28%39%34%33%31%34%29%22 5.05 Medium review 2026-07-29
v3.6" xiPU=dkHI([!+!]) thG=" 4.73 Medium review 2026-07-29
dfb__${98991*97996}__::.x 4.57 Medium review 2026-07-29
dfb{{98991*97996}}xca 5.12 Medium review 2026-07-29
bfgx5182%C0%BEz1%C0%BCz2a%90bcxhjl5182 4.41 Medium review 2026-07-29
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 4.87 Medium review 2026-07-29
<%={{={@{#{${dfb}}%> 4.72 Medium review 2026-07-29
v3.69182912 4.81 Medium review 2026-07-29
v3.6 4.74 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA a099bfe70e3b…
Force block — not fired
Score recovered no
Elapsed 21.5s