Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Inline Translator

iefnjkekehefnnhaallibbadbhkeempj
Risk Score
4.93
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 867
Rating 3.9
Last updated 2023-12-19 (30 months ago)
Manifest version MV3
CSP present ❌ no
Developer pavelretivoy@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; data handling undisclosed.
  • Extension not updated in 30 months; abandoned maintenance window elevates supply-chain risk.
  • Broad host_permissions + content_scripts on all HTTP/HTTPS sites gives access to every page visited.
  • Developer email is free webmail (gmail.com) with no verified business identity.
  • No CSP declared; MV3 default applies but scripting+broad host with no policy is higher-trust requirement.

Evidence

  • broad_host_permissions manifest host_permissions and content_scripts_matches both set to http://*/*, https://*/*; runs on every site.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
  • stale_extension store Last updated December 2023; 30 months since update → +8.5 Maintenance.
  • free_webmail_developer store Developer email pavelretivoy@gmail.com; no verified business domain; domain_age_ct not queried.
  • install_perm_anomaly api 867 installs with HIGH-tier host permissions; small_install_high_perm=true, tail_attack_surface=true.
  • no_cve_no_bad_hosts crx cve_findings_raw empty; bad_host_hits empty; monetization_hits empty; affiliate_hits empty.
  • clean_code_scan crx code_findings_raw empty; obfuscation_score=0.0; only external host is translate.googleapis.com.
  • justified_broad_network manifest Category TranslationTool; sole JS external host is translate.googleapis.com — network aligns with function.

Permissions Breakdown

  • storage low Local key-value storage; low standalone risk.
  • scripting medium Allows injecting JS into pages; medium risk, but paired with broad host access elevates concern.
  • activeTab low Scoped to user-activated tab; limited blast radius.
  • tabs medium Can read tab URLs and titles across all open tabs.
  • http://*/* high Broad host access over all HTTP origins; content scripts injected everywhere.
  • https://*/* high Broad host access over all HTTPS origins; content scripts injected everywhere.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.00
Webstore4.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

v3.6 4.93 Medium review 2026-06-16
v3.4-rev 5.05 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA a1120cc3eb8e…
Force block — not fired
Score recovered no
Elapsed 21.1s