Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Speakex Selected Text - any website

hpodloolnlodljngbclhajmpfpbhmfga
Risk Score
4.16
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Accessibility
Installs 64
Rating 5.0
Last updated 2026-02-03 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer browsnerose@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL failed SSL fetch — treated as no accessible policy; data handling unknown.
  • Install URL hijack: onInstalled opens speakselectiontextextension.shop, a 3rd-party domain.
  • Free-webmail dev (gmail) with generic name 'Extensions' and Google Sites policy — low accountability.
  • Content scripts injected on <all_urls> giving persistent access to every page visited.
  • Extension contacts speakselectiontextextension.shop externally; domain ownership/intent unverified.

Evidence

  • install_url_hijack crx onInstalled redirects to speakselectiontextextension.shop — 3rd-party domain, monetization risk.
  • privacy_policy_fetch_failed api SSLError on https://sites.google.com/view/ext-privacypolicy77/ — policy inaccessible, scored as no policy.
  • free_webmail_developer store Developer email browsnerose@gmail.com; name 'Extensions' is generic; no verified business.
  • content_scripts_all_urls manifest Content scripts match <all_urls> — code runs on every site the user visits.
  • js_external_host crx Extension contacts speakselectiontextextension.shop at runtime; purpose/ownership unverified.
  • is_featured_by_google store Extension carries Google Featured badge — minor trust signal despite other concerns.
  • no_cve_findings crx No bundled JS libraries with known CVEs detected.
  • obfuscation_clean crx obfuscation_score=0.0, code_findings_raw empty — no obfuscation or exfil patterns found.

Permissions Breakdown

  • contextMenus low Adds right-click menu item; core to stated TTS function.
  • tts low Text-to-speech synthesis; matches stated purpose exactly.
  • storage low Persists user voice/speed prefs locally.
  • activeTab low Reads selected text on active tab only; narrow scope.
  • content_scripts <all_urls> medium Script injected into every page; broader than activeTab alone.

Pillar Scores

Permissions1.30
Reputation7.50
Network2.00
Webstore4.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-08 13:52
Listing SHA b97ae6a3fd4f…
Force block — not fired
Score recovered no
Elapsed