Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SQLite browser

iclckldkfemlnecocpphinnplnmijkol
Risk Score
4.04
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 10,000
Rating 4.9
Last updated 2024-12-11 (20 months ago)
Manifest version MV3
CSP present ✅ yes
Developer ix@sqlitebrowser.app
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • install_url_hijack: onInstalled opens sqlitebrowser.app/welcome; uninstall_url_hijack flag set (target null).
  • Stale 20 months with no developer name listed despite verified-publisher badge.
  • External JS hosts include emscripten.org and sqlite.org — third-party origins referenced in manifest.
  • Generic Google privacy policy with third_party_sharing=true scores max privacy risk despite being a dev-tool extension.

Evidence

  • privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — not scoped to this extension; scope_extension=false, data_collection=true, third_party_sharing=true.
  • install_url_hijack crx chrome.runtime.onInstalled opens https://sqlitebrowser.app/welcome; uninstall_url_hijack also flagged (target null).
  • verified_publisher_featured store Extension holds verified-publisher and featured-by-Google badges, capping reputation discount to -1.0 due to monetization/stale invariants.
  • stale_update store Last updated December 2024; 20 months since update — in 6-12mo band (maintenance +3.5) but actually 20mo → +6.0 band.
  • no_developer_name store developer_name is empty string despite verified-publisher status.
  • external_js_hosts crx js_external_hosts: emscripten.org, sqlite.org, sqlitebrowser.app — 3 distinct domains referenced.
  • csp_wasm_only crx CSP restricts script-src to 'self' 'wasm-unsafe-eval' only — appropriate for a WebAssembly SQLite tool.
  • no_permissions crx permissions[], host_permissions[], and content_scripts_matches[] are all empty — minimal capability surface.

Pillar Scores

Permissions0.00
Reputation2.00
Network0.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:46
Listing SHA 6b40dbac3348…
Force block — not fired
Score recovered no
Elapsed