Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Subtitles for Language Learning (Prime Video)

hlofmmmlhfelbfhcpapoackkglljfcnb
Risk Score
2.36
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category TranslationTool
Installs 100,000
Rating 3.8
Last updated 2026-04-04 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@subtitlesfll.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic policy).
  • No CSP defined; two innerHTML DOM-XSS sinks on injected Amazon/Prime Video pages elevate XSS risk.
  • Content scripts run on 19 Amazon domains — broad reach into a high-value shopping/streaming surface.
  • 12 external JS hosts contacted including paypal.me and social/dictionary sites; no geo diversity data.
  • Developer not verified publisher; policy collects+shares data without retention disclosure.

Evidence

  • privacy_policy_generic_collecting_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5-D).
  • dom_sink_innerhtml_no_csp crx Two innerHTML sinks detected; csp_present=false → FIX B applies, each scored at +2.0 but capped.
  • no_csp_mv3 manifest MV3 extension with no content_security_policy; no v2b penalty but FIX B code quality amplifier applies.
  • content_scripts_broad_amazon manifest Content scripts on 19 Amazon/PrimeVideo domains; matches TranslationTool function — justified-broad discount applied.
  • external_host_count crx 12 external JS hosts including paypal.me, twitter.com, multiple dictionary APIs; >3 distinct registrable domains.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; developer identity limited to subtitlesfll.com domain.
  • install_count_100k store 100,000 installs with 3.8 rating; meaningful blast radius on Amazon domains.
  • no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.

Permissions Breakdown

  • storage low Stores user preferences locally; standard low-risk use.
  • background low Persistent service worker; needed for subtitle fetch. Low risk alone.
  • unlimitedStorage low Extended local storage for subtitle caching; no exfil risk on its own.
  • content_scripts on amazon.*+primevideo.com medium DOM access on 19 Amazon/Prime Video domains; matches stated function but broad reach.
  • host_permissions: *.subtitlesfll.com low Developer-owned domain; expected for subtitle API calls.
  • host_permissions: *.opensubtitles.org low Known subtitle provider; matches stated function.
  • host_permissions: clients5.google.com medium Google spell-check/dict API; plausible for language learning but worth noting.

Pillar Scores

Permissions2.30
Reputation5.00
Network2.50
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA efee65eea7db…
Force block — not fired
Score recovered no
Elapsed 28.5s