Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Screen Recorder

hniebljpgcogalllopnjokppmgbhaden
Risk Score
3.67
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Screenshot
Installs 2,000,000
Rating 3.8
Last updated 2024-06-17 (26 months ago)
Manifest version MV3
CSP present ✅ yes
Developer me@eb1.it
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but not scoped to this extension and data_collection=true with third_party_silence=true.
  • Extension not updated in 24 months (stale); 2M install blast radius amplifies any future compromise.
  • new Function() constructor in bundled JS — dynamic code execution risk.
  • innerHTML sink present; CSP is present but policy adequacy remains low.
  • React version 0.20.2 detected — extremely outdated library; no CVEs found but high exploit surface.

Evidence

  • privacy_policy_not_scoped api Policy fetched (13 691 chars) but scope_extension=false, data_collection=true, retention=false — generic policy.
  • stale_extension store Last updated June 2024; months_since_update=24. 2M installs amplify stale risk.
  • function_constructor crx new Function() in main.ff9ff9e3.js — dynamic code execution, likely React/bundler boilerplate.
  • dom_sink_innerhtml crx innerHTML assignment in main.ff9ff9e3.js; CSP present (self-only) limits exploitation.
  • react_outdated crx react@0.20.2 detected via license sidecar — extremely old release, no OSV CVEs flagged.
  • featured_by_google store is_featured_by_google=true; provides moderate reputation trust signal.
  • no_external_hosts crx js_external_hosts empty, no bad/monetization/affiliate hits — clean network surface.
  • csp_present_mv3 manifest script-src 'self'; object-src 'self' — strict CSP, MV3, no remote code loading.

Permissions Breakdown

  • desktopCapture medium Captures screen/audio/video; matches stated function (screen recorder). Medium risk, scoped.

Pillar Scores

Permissions1.50
Reputation4.00
Network0.00
Webstore2.00
Maintenance6.00
Privacy9.00
Code Quality3.50
CVE Exposure0.00

Scoring History

%22fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.05 Medium review 2026-08-15
&#x27;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.32 Medium review 2026-08-15
fsssiedxa<sssiedx 4.47 Medium review 2026-08-15
<fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx 4.22 Medium review 2026-07-29
<fsssiedx{'sssiedx 4.25 Medium review 2026-07-29
<fsssiedx{$"sssiedx 4.74 Medium review 2026-07-29
<fsssiedxh xx psssiedx 4.16 Medium review 2026-07-29
<fsssiedxh&#x22;sssiedx 4.12 Medium review 2026-07-29
fsssiedxhfdsaxax><!--></ScRiPt>asddsssiedx 4.07 Medium review 2026-07-29
fsssiedxh'sssiedx 4.13 Medium review 2026-07-29
sssieddrubricxsx 4.31 Medium review 2026-07-29
v3.6 3.67 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA 6cdca0e3041a…
Force block — not fired
Score recovered no
Elapsed 23.7s