Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

English Vocabulary Builder - DD Vocab

ijgcpnnkjbnpfpbgocnadhiilkhkbhcd
Risk Score
4.53
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 17
Rating
Last updated 2026-05-30 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer harrywangma@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail) with no developer name; no verified publisher badge.
  • Privacy policy fetched but does not scope to this extension or disclose data collection.
  • Content script runs on <all_urls> giving broad page-read surface across every site.
  • innerHTML sinks without CSP increase DOM-XSS risk if page content is used as input.
  • YouTube brand mention flagged as impersonation; confirmed_owner is false.

Evidence

  • free_webmail_dev_no_name store developer_email=harrywangma@gmail.com; developer_name empty; no verified publisher.
  • privacy_policy_insufficient api Policy fetched (636 chars); scope_extension=false, data_collection=false — generic, not extension-scoped.
  • content_scripts_all_urls manifest content_scripts_matches=[<all_urls>]; runs on every page visited by user.
  • dom_xss_no_csp crx Two innerHTML sinks in content.js and popup.js; csp_present=false amplifies risk.
  • brand_impersonation_youtube store brand_mention.is_impersonation=true for YouTube; developer domain is gmail.com, confirmed_owner=false.
  • install_url_hijack manifest onInstalled opens https://deltadailyapp.com; minor monetization/tracking signal.
  • gemini_api_host crx Outbound requests to generativelanguage.googleapis.com; selected text sent to external AI API.
  • very_low_installs store Only 17 installs; no rating; minimal community trust signal.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • activeTab low Access to current tab only on user gesture; scoped.
  • storage low Local extension storage; no cross-site exfil risk alone.
  • notifications low Can display desktop notifications; nuisance risk only.
  • alarms low Scheduling API; used for spaced repetition reminders.
  • scripting medium Allows dynamic script injection; paired with content_scripts on <all_urls>.
  • host_permissions: https://deltadailyapp.com/* low Dev's own domain; expected for vocab sync.
  • host_permissions: https://generativelanguage.googleapis.com/* medium Sends text to Google Gemini API; data leaves browser.
  • content_scripts_matches: <all_urls> medium Content script runs on every page; broad read surface despite narrow stated function.

Pillar Scores

Permissions3.30
Reputation7.00
Network2.50
Webstore4.00
Maintenance1.50
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-10 11:38
Listing SHA 48909ae77c9e…
Force block — not fired
Score recovered no
Elapsed