Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ScreenCapX - Full Page Screenshot

ihfedmikeegmkebekpjflhnlmfbafbfe
Risk Score
4.34
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Screenshot
Installs 6,000
Rating 4.5
Last updated 2026-08-21
Manifest version MV3
CSP present ❌ no
Developer gee.linwood956@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail Gmail dev with no verified identity — high reputation risk floor.
  • Privacy policy fetched but not scoped to this extension; admits data collection and third-party sharing — scores maximum privacy risk.
  • Uninstall URL hijack AND install URL hijack both flagged — classic monetization/traffic-stealing pattern.
  • declarativeNetRequest + <all_urls> on a screenshot tool is scope-mismatched — can intercept/modify requests on every site.
  • Description promises recording capability but extension lacks tabCapture/desktopCapture — description vs permission mismatch.

Evidence

  • free_webmail_dev_no_business store Developer email gee.linwood956@gmail.com; developer_name matches email prefix; no verified business identity.
  • install_and_uninstall_url_hijack crx uninstall_url_hijack=true and install_url_hijack=true; install target is internal designBoard page.
  • privacy_policy_generic_with_data_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — admits sharing without extension scope.
  • description_promise_mismatch store Promises recording but lacks tabCapture/desktopCapture; description_promise.mismatches non-empty.
  • dom_sink_innerhtml_no_csp crx innerHTML sink in content.js on <all_urls> with csp_present=false — elevated DOM-XSS risk.
  • declarativeNetRequest_scope_mismatch manifest declarativeNetRequest declared on a screenshot tool with <all_urls> — unexpected network-modification capability.
  • 12_external_js_hosts crx 12 external JS host references including buymeacoffee.com, github.com, hertzen.com, reddit.com, screencapx.co.
  • function_constructor_code_finding crx new Function() constructor detected in designBoard.js — potential dynamic code execution path.

Permissions Breakdown

  • storage low Standard local data persistence, low risk.
  • tabs medium Allows reading tab URLs and metadata; needed for screenshot but gives broad visibility.
  • declarativeNetRequest medium Can modify/block network requests; unexpected for a screenshot tool.
  • unlimitedStorage low Allows large local data storage; minor risk alone.
  • <all_urls> high Broad host access enabling content scripts on every page, major attack surface.

Pillar Scores

Permissions5.50
Reputation7.50
Network2.00
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:10
Listing SHA c6a6c4baa804…
Force block — not fired
Score recovered no
Elapsed