Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Looper for YouTube

iggpfpnahkgpnindfkdncknoldgnccdg
Risk Score
2.77
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 400,000
Rating 4.6
Last updated 2026-04-23 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer email@alvinhkh.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection + third-party sharing without scoping to this extension — highest risk signal.
  • Brand impersonation flag on 'YouTube' name; developer is not confirmed YouTube/Google affiliate.
  • CSP permits frame-src/img-src to Facebook and Twitter — unnecessary for a loop utility.
  • Developer name field is blank, reducing accountability despite verified publisher status.
  • 400K installs means any future compromise or policy change has large blast radius.

Evidence

  • privacy_policy_generic_with_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy D clause → +10.0
  • brand_impersonation store brand_mention.is_impersonation=true, brands=['youtube'], confirmed_owner=false; featured badge applied.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied to Reputation.
  • csp_broad_img_frame manifest CSP allows img-src/frame-src to facebook.com, twitter.com, gstatic.com beyond core YouTube loop function.
  • no_bad_hosts_no_cve api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], cve_findings_raw=[] — clean threat intel.
  • minimal_permissions manifest Only 'storage' + content_scripts scoped to *.youtube.com. No host_permissions, no HIGH-tier perms.
  • recently_updated store months_since_update=2; maintenance score=0.0.
  • obfuscation_clean crx obfuscation_score=0.0, code_findings_raw=[], 3 JS files scanned — no malicious code signals.

Permissions Breakdown

  • storage low Stores user preferences (loop settings). No cross-site exposure.
  • content_scripts *://*.youtube.com/* low Scoped to YouTube only; matches stated loop functionality.

Pillar Scores

Permissions0.60
Reputation3.50
Network2.00
Webstore3.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA 4c745aadc4d8…
Force block — not fired
Score recovered no
Elapsed 21.6s