Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

CSS Inspector

ihadgmliliipmlmffednicabkkfdpfli
Risk Score
4.40
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 62
Rating
Last updated 2024-03-11 (27 months ago)
Manifest version MV3
CSP present ❌ no
Developer fibril_form0k@icloud.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (scope_extension=false, admits data collection and 3rd-party sharing) — scores maximum privacy risk.
  • Extension last updated 27 months ago; abandoned or zombie risk with no active maintenance.
  • Developer email is iCloud address (fibril_form0k@icloud.com) with no verifiable business identity.
  • No CSP present on MV3 extension; no code findings detected but no policy protection layer.
  • Very low install count (62) with zero ratings; no community validation signal.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — not scoped to this extension.
  • maintenance_stale store Last updated March 2024; 27 months since update — falls in 24-36mo band (+8.5).
  • developer_identity_weak store Developer email fibril_form0k@icloud.com; free-webmail provider, no verified business website.
  • no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit policy declared.
  • low_installs_no_ratings store Only 62 installs, 0 ratings — no community trust signal available.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, no external JS hosts — clean scan.
  • permissions_minimal manifest Only activeTab and scripting declared; no host_permissions or broad URL access.
  • no_bad_hosts_or_monetization api threat_intel shows empty bad_host_hits, affiliate_hits, and monetization_hits.

Permissions Breakdown

  • activeTab low Grants access only to the current tab on user action; minimal blast radius.
  • scripting medium Allows injecting scripts into pages; scope limited by activeTab, but still capable of DOM access.

Pillar Scores

Permissions1.30
Reputation6.50
Network0.00
Webstore0.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA 4e215e40de91…
Force block — not fired
Score recovered no
Elapsed 19.2s