Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Smart Adblocker

iojpcjjdfhlcbgjnpngcmaojmlokmeii
Risk Score
2.19
Risk Level: Low
Recommendation: ✅ ALLOW
Category Adblock
Installs 90,000
Rating 4.1
Last updated 2026-06-11 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@smartadblocker.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • install_url_hijack: onInstalled opens youtube.com — benign target but hijack pattern present
  • No developer name listed in store; reduces accountability
  • Content scripts on <all_urls> including YouTube give broad DOM access on every page
  • js_external_hosts includes react.dev — MV3 + no CSP means external JS host is a supply-chain risk
  • Privacy policy discloses third-party sharing; users should review data flows

Evidence

  • verified_publisher + featured store Both verified-publisher badge and Google featured badge present; strong positive trust signal.
  • install_url_hijack manifest onInstalled opens https://www.youtube.com/ — hijack pattern exists, target is benign but worth flagging.
  • host_permission_all_urls manifest <all_urls> host permission with content_scripts on all URLs; justified by Adblock category.
  • js_external_hosts crx react.dev, smartadblocker.com, www.youtube.com listed as external JS hosts. react.dev is a CDN risk.
  • no_csp manifest content_security_policy is null (MV3 default applies, but no explicit hardening).
  • privacy_policy_classification api Policy fetched, scoped to extension, discloses collection, retention, and third-party sharing.
  • code_findings_raw_empty crx 16 JS files scanned; no suspicious patterns detected, obfuscation_score=0.0.
  • no_developer_name store developer_name is empty string; reduces accountability despite verified publisher badge.

Permissions Breakdown

  • declarativeNetRequest medium Core adblock capability; blocks network requests. Expected for Adblock category.
  • declarativeNetRequestFeedback low Read-only feedback on blocked requests; minor telemetry risk.
  • storage low Local config persistence only.
  • tabs medium Can read tab URLs and metadata across all open tabs.
  • <all_urls> (host_permission) high Broad host access required for adblock function; justified but amplifies any compromise.

Pillar Scores

Permissions3.50
Reputation2.00
Network2.50
Webstore3.50
Maintenance0.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:10
Listing SHA cf9bdc456398…
Force block — not fired
Score recovered no
Elapsed