Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

PopUpOFF - Popup and overlay blocker

ifnkdbpmgkdbfklnbfidaackdenlmhgh
Risk Score
5.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Adblock
Installs 40,000
Rating 4.5
Last updated 2023-08-10 (34 months ago)
Manifest version MV3
CSP present ❌ no
Developer RomanistHere@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (scope_extension=false, admits data collection & 3rd-party sharing) — +10.0 privacy pillar.
  • Extension last updated 34 months ago — high staleness risk, no recent security patches.
  • Broad content_scripts on <all_urls> with no CSP; no MV2 penalty (MV3) but surface is wide.
  • Developer email is free webmail (gmail.com) with empty developer_name; limited accountability.
  • Description promises ad/popup blocking but lacks declarativeNetRequest/webRequest — description mismatch flagged.

Evidence

  • privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true — not scoped to this extension.
  • staleness store Last updated August 2023; 34 months since update triggers +8.5 maintenance score.
  • broad_host_permissions manifest host_permissions include http://*/ and https://*/ with content_scripts on <all_urls>.
  • no_csp manifest content_security_policy is null; MV3 so no +2.0 network penalty, but no inline-script protection.
  • developer_identity store developer_name is empty; email is RomanistHere@gmail.com (free webmail). Verified publisher badge present.
  • description_mismatch store description_promise reports mismatch: promises ad-blocking but lacks declarativeNetRequest/webRequest.
  • install_url_hijack crx onInstalled opens https://popupoff.org/tutorial?source=chrome — own domain, low severity but flagged.
  • clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, no CVEs, no bad/affiliate/monetization hosts.

Permissions Breakdown

  • activeTab low Scoped to user-invoked tab; low blast radius.
  • storage low Local settings persistence only.
  • tabs medium Can read tab URLs/titles across all open tabs.
  • contextMenus low UI-only menu injection, no data access.
  • http://*/ high Broad host access to all HTTP sites via content scripts.
  • https://*/ high Broad host access to all HTTPS sites via content scripts.

Pillar Scores

Permissions4.00
Reputation3.50
Network2.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA d9e05cb3fbb7…
Force block — not fired
Score recovered no
Elapsed 22.6s