Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

goormIDE: Powerful Code Editor with Container

ijjkemiomhkpfaekhcjladhkdojlaogc
Risk Score
5.02
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 8,000
Rating 4.5
Last updated 2022-05-24 (49 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@goorm.io
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Extension not updated in 49 months — zombie state; any future compromise is undetected.
  • No content security policy (MV3 with no CSP; network behavior +2.0 applied).
  • Privacy policy fetched but does not scope to this extension and flags no data collection — generic corporate policy.
  • cookies permission combined with *.goorm.io host access allows full session cookie read on that domain.
  • No developer display name registered; minor accountability gap despite verified email domain.

Evidence

  • verified_publisher store Verified publisher badge present; developer domain goorm.io resolves and is not throwaway.
  • maintenance_stale store Last updated May 2022; 49 months since update — >36mo band, score 10.0.
  • no_csp manifest content_security_policy is null; MV3 +2.0 network penalty applied per v2 calibration fix (b).
  • privacy_policy_scope api Policy fetched, scope_extension=false, data_collection=false, third_party_sharing=false → +9.0 privacy.
  • cookies_permission manifest cookies declared with host_permissions *.goorm.io — scoped but high-sensitivity permission.
  • js_external_host_fb_me crx fb.me appears in js_external_hosts; no code_findings referencing it, low immediate risk.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 8K installs with high-tier permission (cookies).
  • no_cve_findings crx cve_findings_raw empty; library versions unknown via sourcemap only — no CVE penalties.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; moderate privacy exposure.
  • cookies high Access to cookies on host_permissions scope (*.goorm.io); session token risk.
  • https://*.goorm.io/* medium Scoped to developer's own domain only; limited blast radius.

Pillar Scores

Permissions3.00
Reputation3.50
Network2.00
Webstore2.00
Maintenance10.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA a715a110da4c…
Force block — not fired
Score recovered no
Elapsed 19.9s