Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Manuals Viewer

ieihbaicbgpebhkfebnfkdhkpdemljfb
Risk Score
7.24
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 138
Rating
Last updated 2024-06-09 (25 months ago)
Manifest version MV3
CSP present ❌ no
Developer wilkinsonvalentine272@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail) with no verified identity, broad all-URLs scripting capability — high option value for malicious pivot.
  • Uninstall URL hijack flag set — extension registers a 3rd-party URL on uninstall, a monetization/tracking pattern.
  • Privacy policy admits data collection AND third-party sharing but is NOT scoped to this extension — worst-case disclosure.
  • Extension stale 25 months with no rating data and only 138 installs — tail-attack-surface with high permissions.
  • No CSP combined with broad scripting + tabs + declarativeNetRequest enables full man-in-the-middle of every page.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() call detected — routes users to 3rd-party on uninstall; monetization/tracking signal.
  • broad_host_permissions manifest host_permissions and content_scripts_matches both set to http://* + https://* giving full page access.
  • free_webmail_developer store Developer email wilkinsonvalentine272@gmail.com; no verified publisher badge; numbered-alias pattern.
  • privacy_policy_generic_admits_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy.
  • maintenance_stale store Last updated June 2024, 25 months ago — 24-36mo band triggers +8.5 maintenance score.
  • install_perm_anomaly api 138 installs with HIGH-tier permissions: small_install_high_perm=true, tail_attack_surface=true.
  • no_csp manifest content_security_policy is null (MV3 strict default applies, no extra network penalty, but amplifies other risks).
  • numbered_alias_email store Developer email matches numbered-alias pattern (wilkinsonvalentine272) — webstore +3.0 signal.

Permissions Breakdown

  • storage low Stores local extension data; low standalone risk.
  • tabs medium Can read tab URLs and metadata across all open tabs.
  • scripting high Allows JS injection into any page via broad host_permissions; high capability.
  • declarativeNetRequest medium Can intercept and redirect network requests declaratively.
  • http://*/* high Broad host access: content scripts run on every HTTP page.
  • https://*/* high Broad host access: content scripts run on every HTTPS page.

Pillar Scores

Permissions8.00
Reputation8.50
Network4.00
Webstore7.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-29 13:19
Listing SHA a299796f567c…
Force block — not fired
Score recovered no
Elapsed