Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Simple Tracker Blocker

igndlohkanjlkpafiecjdijfngdkjnmj
Risk Score
5.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 18
Rating
Last updated 2023-10-31 (32 months ago)
Manifest version MV3
CSP present ❌ no
Developer alissonsilvamorimduarte2@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — scope_extension=false, data_collection=true, third_party_sharing=true; not scoped to this extension at all.
  • Extension last updated 32 months ago; effectively abandoned with no maintenance signal.
  • Free-webmail developer (gmail) with no verified business identity raises accountability concerns.
  • Description promises tracker-blocking but lacks declarativeNetRequest/webRequest — functional mismatch.
  • No CSP defined (MV3 so no +2.0 network penalty, but no hardening either).

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy (v3.5 rule D).
  • maintenance_stale store Last updated October 2023; months_since_update=32 — falls in 24-36mo band, +8.5 Maintenance.
  • reputation_free_webmail store Developer email is gmail.com with no business website; free-webmail+no verified org raises Reputation floor to 7.5.
  • description_promise_mismatch store Promises ad/tracker-blocking but declares only activeTab — no declarativeNetRequest or webRequest present.
  • no_csp manifest content_security_policy is null; MV3 so no +2.0 network penalty, but no explicit hardening.
  • minimal_permissions manifest Only activeTab declared; no host permissions, no content scripts — low capability surface.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — no malicious code signals.
  • very_low_installs store Only 18 installs; negligible blast radius but suggests untested/prototype state.

Permissions Breakdown

  • activeTab low Grants access only to the current tab on user gesture; limited scope.

Pillar Scores

Permissions0.30
Reputation7.50
Network2.00
Webstore2.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA 17ceb20c4e4d…
Force block — not fired
Score recovered no
Elapsed 20.9s