Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Preact Developer Tools

ilcajpmogmhpliinlbcdebhbcanbghmd
Risk Score
4.09
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 8,000
Rating 4.5
Last updated 2025-03-31 (15 months ago)
Manifest version MV3
CSP present ✅ yes
Developer preact@marvinh.dev
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • Broad <all_urls> host permissions + content scripts on all pages despite dev-tools function.
  • Last updated 15 months ago; moderate staleness for an extension with high host access.
  • Not a verified publisher; marvinh.dev domain resolves but is individual dev, not recognized org.
  • tail_attack_surface flagged: small install base (~8K) with HIGH-tier permissions.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar.
  • host_permissions_broad manifest <all_urls> in host_permissions and content_scripts_matches; DeveloperTools discount applies (-1.5).
  • maintenance_stale store 15 months since last update → +6.0 maintenance pillar (6-12mo bracket).
  • is_featured_by_google store Featured badge present; -2.0 reputation discount applied.
  • no_bad_hosts_or_cves crx bad_host_hits=[], cve_findings_raw=[], js_external_hosts=[], obfuscation_score=0.0.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 8K installs with high-tier permission.
  • csp_present_mv3 manifest CSP: script-src 'self'; object-src 'self'. MV3 with strict CSP — no network penalty.
  • operator_cluster_clean api sibling_count=0, no monetization/affiliate hits, domain resolves, looks_throwaway=false.

Permissions Breakdown

  • scripting medium Can inject JS into pages; paired with <all_urls> increases reach significantly.
  • storage low Local extension storage; no exfil risk on its own.
  • <all_urls> (host_permissions) high Broad host access across all sites; enables scripting injection everywhere.
  • <all_urls> (content_scripts) high Content scripts run on every page; broad reach for a dev-tools extension.

Pillar Scores

Permissions4.00
Reputation3.50
Network0.00
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA 2cf4434f1c54…
Force block — not fired
Score recovered no
Elapsed 21.1s