Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Just JSON Viewer

hpmmjcpbalflfgmgloddnkeibocfdjcn
Risk Score
5.17
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 485
Rating 5.0
Last updated 2023-04-03 (38 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@herotofu.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned: 38 months since last update, well past 36-month stale threshold.
  • Privacy policy not scoped to this extension; data_collection field false but no retention disclosure.
  • innerHTML DOM sink present and no CSP — XSS risk if JSON input is malicious.
  • No developer name listed in store; reduces accountability.
  • Install-URL opens herotofu.com onboarding page on install (minor hijack signal).

Evidence

  • stale_extension store Last updated April 2023; 38 months since update triggers max maintenance score of 10.0.
  • dom_sink_innerhtml_userctrl crx innerHTML sink in viewer JS; no CSP present, elevating XSS risk to +2.0 code quality.
  • no_csp manifest MV3 extension; no content_security_policy declared. DOM sink risk amplified.
  • privacy_policy_not_scoped api Policy fetched but scope_extension=false and no retention clause; scores +9.0 privacy.
  • install_url_hijack crx onInstalled opens https://herotofu.com/extensions?chromeOnboarding=just-json-viewer (+2.0 webstore).
  • no_developer_name store developer_name is empty string; +1.0 reputation penalty.
  • no_bad_hosts_no_cves api threat_intel bad_host_hits and cve_findings_raw both empty; no CVE or threat-intel risk.
  • developer_domain_resolves api herotofu.com resolves, not throwaway; partial reputation mitigation.

Permissions Breakdown

  • activeTab low Grants access to the current tab only on user action; narrow scope.
  • contextMenus low Adds right-click menu items; no data access on its own.
  • scripting medium Can inject scripts into pages; paired with activeTab limits scope to user-triggered actions.

Pillar Scores

Permissions1.60
Reputation5.50
Network0.00
Webstore2.00
Maintenance10.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA 232437436c58…
Force block — not fired
Score recovered no
Elapsed 22.3s