Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Habitica Pomodoro SiteKeeper

iaanigfbldakklgdfcnbjonbehpbpecl
Risk Score
4.63
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 10,000
Rating 4.7
Last updated 2025-08-25 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer ofex.create@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host access (*://*/*) combined with scripting allows code injection across all visited sites.
  • Privacy policy URL fetch failed — policy content unverifiable; scored as unfetched (+10.0 privacy).
  • Free-webmail developer (gmail) with no developer name reduces accountability.
  • Description promises ad-blocking but lacks declarativeNetRequest/webRequest — permission mismatch.
  • DOM-XSS sink (innerHTML from variable) with no CSP present increases XSS exploitability.

Evidence

  • broad_host_access manifest host_permissions includes *://*/*; paired with scripting enables cross-site code injection.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false due to HTTPError; policy content cannot be assessed.
  • free_webmail_dev_no_name store developer_email=ofex.create@gmail.com, developer_name empty; no verified business identity.
  • description_mismatch store Promises ad-blocking but lacks declarativeNetRequest or webRequest permissions.
  • dom_xss_sink_no_csp crx innerHTML used on user-controlled task title in popup.js; no CSP present amplifies risk.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partially mitigates reputation risk.
  • no_bad_hosts_or_affiliates api threat_intel shows no bad_host_hits, affiliate_hits, or monetization_hits.
  • no_cve_findings crx cve_findings_raw empty; jquery 3.6.0 bundled but no CVEs flagged for this version.

Permissions Breakdown

  • storage low Stores local timer/task state; standard low-risk.
  • unlimitedStorage low Extended local storage; no exfil risk alone.
  • notifications low Pomodoro alerts; expected for timer app.
  • scripting medium Can inject scripts into pages; elevated with broad host access.
  • tabs medium Can read tab URLs and metadata; needed for site-blocking feature.
  • offscreen low Background audio/timer support; low standalone risk.
  • *://*/* high Broad host access across all sites; combined with scripting raises risk.

Pillar Scores

Permissions5.50
Reputation4.50
Network2.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA e4b3b9a101a5…
Force block — not fired
Score recovered no
Elapsed 22.7s