Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Pomodoro Grande: Advanced Productivity Timer

hmkklgcpkihbecjbohepediganhefdof
Risk Score
4.78
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 1,000
Rating 4.6
Last updated 2026-03-24 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer gemmueldelacruz@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
  • content_scripts run on <all_urls> — full page access on every site visited.
  • No CSP declared; DOM-XSS sink (innerHTML) in sites.js has no mitigating policy.
  • Free-webmail developer (gmail.com) with no verified business presence or publisher badge.
  • Description claims ad-blocking but extension lacks declarativeNetRequest/webRequest — promise/permission mismatch.

Evidence

  • content_scripts_matches=<all_urls> manifest Content script injected into every URL; broad reach for a productivity timer.
  • privacy_policy_generic store Policy URL is myaccount.google.com — Google's own policy, not scoped to this extension.
  • privacy_policy_classification api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • dom_sink_innerhtml_userctrl crx sites.js: innerHTML assigned from variable; no CSP to mitigate DOM-XSS.
  • no_csp manifest content_security_policy is null; MV3 default is strict but no explicit CSP set.
  • description_promise_mismatch store Description promises website blocker/ad-blocking but declarativeNetRequest/webRequest absent.
  • free_webmail_developer store Developer email is gemmueldelacruz@gmail.com; no verified publisher badge.
  • is_featured_by_google store Extension carries Google Featured badge, partially mitigating reputation risk.

Permissions Breakdown

  • storage low Stores timer/task state locally; standard for productivity apps.
  • notifications low Pomodoro timer break alerts; expected for this category.
  • offscreen low Used for audio playback (focus music) in background; low standalone risk.
  • content_scripts <all_urls> high Injects JS into every page; required for site blocker but broad reach.

Pillar Scores

Permissions3.50
Reputation6.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA af0e7af454c8…
Force block — not fired
Score recovered no
Elapsed 23.4s