Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Speed Reading

ihbdojmggkmjbhfflnchljfkgdhokffj
Risk Score
4.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category ReaderMode
Installs 30,000
Rating 4.8
Last updated 2024-12-10 (18 months ago)
Manifest version MV3
CSP present ✅ yes
Developer azadev.team@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing without scoping to this extension (worst-case privacy score).
  • Free-webmail developer (gmail) with no named developer — accountability gap.
  • scripting + <all_urls> + content_scripts on all URLs gives full read/write access to every page.
  • CSP connect-src includes amplitude.com, sentry.io, logflare.app — analytics/logging on all browsing sessions.
  • Months since update = 18 — borderline stale; verified publisher cap may not fully apply.

Evidence

  • broad_host_access manifest host_permissions <all_urls> + content_scripts *://*/* — extension runs on every page the user visits.
  • privacy_policy_classification api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → worst-case: admits sharing without scoping.
  • free_webmail_developer store developer_email=azadev.team@gmail.com, developer_name empty; no verified business identity beyond publisher badge.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; partially mitigates reputation concern.
  • csp_connect_src_analytics crx CSP connect-src allows amplitude.com, sentry.io, logflare.app — telemetry endpoints active on all sites.
  • geo_diversity api JS hosts span 4 countries (CA, IN, SG, US); +1.5 network penalty for non-VPN/translation category.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; no malicious code signals detected.
  • maintenance_borderline store months_since_update=18; exactly at 18mo boundary — verified-publisher cap applies but staleness noted.

Permissions Breakdown

  • storage low Stores user preferences locally; low standalone risk.
  • contextMenus low Adds right-click menu items; minimal risk.
  • scripting high Programmatic script injection into pages; HIGH when combined with <all_urls>.
  • <all_urls> (host_permission) high Broad host access across every site; enables reading/modifying all page content.
  • *://*/* (content_scripts) high Content script injected on all URLs; REACH across every page visited.

Pillar Scores

Permissions5.50
Reputation5.50
Network3.50
Webstore1.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA 47306f695102…
Force block — not fired
Score recovered no
Elapsed 21.1s