Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DirectStayz: Book hotels directly, save money and unlock benefits

imbiddkienbjbdoaclimfhdhbpbhnabf
Risk Score
5.01
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 1,000
Rating 4.9
Last updated 2025-05-05 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer matcha.squad1@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, yet admits data collection and third-party sharing (+10.0 privacy).
  • Uninstall and install URL hijack flags set, indicating extension opens/redirects to 3rd-party URLs on install/uninstall events.
  • Affiliate network host (www.awin1.com) in js_external_hosts signals monetization via affiliate-link injection on booking.com.
  • Free-webmail developer (gmail) with no verified business; developer domain is gmail.com, no independent business presence.
  • Stale update (14 months) combined with MV3 and no CSP raises residual governance risk.

Evidence

  • install/uninstall URL hijack crx uninstall_url_hijack=true and install_url_hijack=true; targets not resolved but pattern is monetization/tracking.
  • affiliate host detected crx www.awin1.com present in js_external_hosts — affiliate network indicating commission-based link injection.
  • generic Google privacy policy store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free-webmail developer, no verified publisher store Developer email matcha.squad1@gmail.com; verified_publisher=false; is_featured_by_google=false.
  • multiple external JS hosts beyond stated function crx 10 external hosts including plausible-1.matcha-squad.xyz, pocketbase-1.matcha-squad.xyz, edge.truesign.ai, awin1.com.
  • stale extension store Last updated May 2025; months_since_update=14, in the 12-24mo maintenance band (+6.0).
  • no content_security_policy manifest csp_present=false on MV3 extension; no CSP declared.
  • obfuscation and code findings clean crx obfuscation_score=0.0; code_findings_raw empty; 12 JS files scanned with no AST findings.

Permissions Breakdown

  • storage low Stores local state; no user-data exfil risk on its own.
  • host: https://api.getdirecto.com/* low Narrow host permission to single API domain matching stated function.
  • content_scripts: booking.com medium Runs JS on booking.com pages; can read page content including search/hotel data.

Pillar Scores

Permissions1.30
Reputation6.50
Network3.50
Webstore7.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-08 14:39
Listing SHA eb0e5865d597…
Force block — not fired
Score recovered no
Elapsed