Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Translator

icchadngbpkcegnabnabhkjkfkfflmpj
Risk Score
4.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 10,000
Rating 4.3
Last updated 2025-02-23 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer henrikdoiakc@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail developer email with 3rd-party privacy policy domain (app-loady.com) — no verified business identity.
  • install_url_hijack=true: extension opens 3rd-party URL on install, classic monetization/adware pattern.
  • scripting + <all_urls> content_scripts allow code injection on every site the user visits.
  • Privacy policy admits data collection and third-party sharing but no retention period disclosed.
  • 18 months since last update; extension at maintenance boundary with broad host access.

Evidence

  • install_url_hijack manifest install_url_hijack=true; extension redirects user on install to 3rd-party URL — monetization/adware indicator.
  • developer_identity store Dev email henrikdoiakc@gmail.com (free webmail); privacy policy on app-loady.com — unrelated domain, no verified business.
  • broad_host_access manifest <all_urls> host_permission + content_scripts on <all_urls> + scripting permission — full-page access on all sites.
  • privacy_policy_classification api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • js_external_hosts crx 8 external JS hosts including getbootstrap.com, jquery.org, popper.js.org — CDN references in extension code.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension with external host references.
  • maintenance store Last updated February 23, 2025; 18 months since update — at 6-month maintenance penalty boundary.
  • obfuscation_code_quality crx obfuscation_score=0.0; code_findings_raw empty; 18 JS files scanned — no malicious code detected.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • activeTab low Scoped to current tab on user action; limited exposure.
  • storage low Stores extension settings locally.
  • tabs medium Can read tab URLs and metadata across sessions.
  • system.display low Reads display configuration; unusual for a translator but low risk.
  • declarativeNetRequest medium Can block/redirect network requests; potential for content manipulation.
  • scripting medium Can inject scripts into pages; paired with <all_urls> increases reach.
  • <all_urls> (host_permission) high Broad host access across all sites; amplifies scripting and declarativeNetRequest risk.

Pillar Scores

Permissions5.50
Reputation6.50
Network4.00
Webstore4.00
Maintenance6.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:52
Listing SHA ffba03cad81b…
Force block — not fired
Score recovered no
Elapsed