Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Clipboard History

hocnnmhgcikjadmcgimjfabidalgejio
Risk Score
5.58
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 3,000
Rating 4.0
Last updated 2023-10-29 (32 months ago)
Manifest version MV3
CSP present ❌ no
Developer arsalan.sosa2020@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • Content scripts injected on all HTTP/HTTPS pages despite clipboard-only stated function.
  • Extension is 32 months stale (no update since Oct 2023) — supply-chain or abandonment risk.
  • Gmail developer with no business domain; free-webmail identity raises accountability concerns.
  • DOM-XSS sink (innerHTML) in popup.js with no CSP — potential for stored-clipboard payload execution.

Evidence

  • broad_content_scripts manifest content_scripts_matches covers http://*/* and https://*/* — all sites, despite no stated need.
  • generic_privacy_policy store Policy URL is myaccount.google.com — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email arsalan.sosa2020@gmail.com; no business domain; domain_age_ct not queried.
  • stale_extension store Last updated October 2023; 32 months since update — zombie-range staleness.
  • dom_xss_sink crx popup.js uses innerHTML with variable content; no CSP present (MV3 but csp_present=false).
  • install_url_hijack crx install_url_hijack=true; onInstalled redirects to /pages/popup.html (internal, not 3rd-party).
  • is_featured_by_google store Extension carries Google Featured badge — partial trust signal, partially offsets reputation risk.
  • no_bad_hosts api threat_intel shows no bad_host_hits, no monetization_hits, no affiliate_hits.

Permissions Breakdown

  • storage low Stores clipboard history locally; expected for this category.
  • content_scripts http://*/* https://*/* high Broad content script injection on all sites — high reach for a clipboard tool.

Pillar Scores

Permissions3.30
Reputation6.50
Network2.00
Webstore3.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA aa3febd240e4…
Force block — not fired
Score recovered no
Elapsed 21.2s