Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Quick Image Search

ihbfgploaolhdcfohgmkgeelahfghngd
Risk Score
3.26
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 30,000
Rating 4.0
Last updated 2025-12-10 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer maartenlaurs+chrome-web-store@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension.
  • Developer email is free-webmail (gmail) with no verified business identity and no developer name listed.
  • Extension uses Google Lens/Google Search as external hosts with no CSP; contact surface is narrow but unaudited.
  • Verified publisher + featured badges reduce reputation risk, but generic privacy policy remains a gap.
  • 30k installs amplify blast radius if extension behaviour changes in future update.

Evidence

  • privacy_policy_generic store Policy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.
  • verified_publisher + featured store verified_publisher=true AND is_featured_by_google=true; reputation discounts applied but capped due to generic privacy policy.
  • free_webmail_dev store Developer email maartenlaurs+chrome-web-store@gmail.com; no developer name; free webmail +1.5 reputation.
  • permissions_minimal manifest Only contextMenus declared; no host_permissions, no content_scripts. Very low capability surface.
  • external_hosts crx JS contacts lens.google.com and www.google.com only — consistent with image search function; 1 country (US).
  • no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty. Clean code surface.
  • maintenance store Last updated December 10, 2025; months_since_update=6 → +1.5 maintenance score.
  • no_bad_hosts_no_affiliates api threat_intel bad_host_hits=[], affiliate_hits=[], monetization_hits=[]. No threat-intel signals.

Permissions Breakdown

  • contextMenus low Adds right-click menu entries; no data access on its own.

Pillar Scores

Permissions0.30
Reputation5.50
Network0.00
Webstore1.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA 09d2978134f1…
Force block — not fired
Score recovered no
Elapsed 19.3s