Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Live editor for CSS, Less & Sass - Magic CSS

ifhikkcafabcgolfjegfcgloomalapol
Risk Score
5.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 70,000
Rating 4.6
Last updated 2024-07-24 (23 months ago)
Manifest version MV3
CSP present ✅ yes
Developer webextensions.org@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — does not scope data practices to this extension at all.
  • eval_user_input and function_constructor in bundled Less compiler; arbitrary code execution risk if fed hostile input.
  • dom_sink_innerhtml_userctrl combined with eval findings elevates DOM-XSS risk (FIX B).
  • No developer name listed; gmail dev email with no verified business identity.
  • 23 months since last update approaches stale threshold; verified-publisher discount capped under v3.5 invariant 0c (>18mo).

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google generic policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D).
  • eval_and_function_constructor crx eval_user_input (+2.5) and function_constructor (+2.5) found in Less compiler bundle; high code-quality risk.
  • dom_sink_innerhtml_userctrl_elevated crx innerHTML sink present AND eval finding also present → +2.0 (FIX B).
  • developer_identity store No developer name; gmail email webextensions.org@gmail.com; free-webmail dev raises reputation score.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied but capped at -1.0 due to >18mo staleness (invariant 0c).
  • maintenance_staleness store 23 months since update → +6.0 maintenance pillar (6–12mo band overshoot; 12-24mo = +6.0).
  • no_bad_hosts_or_cves crx cve_findings_raw empty, bad_host_hits empty, affiliate_hits empty, monetization_hits empty.
  • csp_present_mv3 manifest script-src 'self'; object-src 'self' — strict CSP, MV3; no remote code loading penalty.

Permissions Breakdown

  • activeTab medium Grants access to the active tab on user interaction; limited but enables DOM/script access.
  • storage low Stores extension state locally; low direct risk.
  • unlimitedStorage low Allows large local storage; minor abuse vector for data caching.
  • scripting medium Can inject scripts into pages; necessary for CSS editor but elevated capability.
  • offscreen low Creates offscreen documents for background processing; low risk without host perms.

Pillar Scores

Permissions2.30
Reputation5.50
Network1.50
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA ff0fad84c219…
Force block — not fired
Score recovered no
Elapsed 30.0s