Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Inbox Firewall

iomcnbgephfbopcnhgiophdaobmikfep
Risk Score
3.29
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Security
Installs
Rating
Last updated 2026-04-28 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@neurear.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy (not scoped to this extension); admits data collection and 3rd-party sharing without extension-specific disclosure.
  • Content script on Gmail means extension can read sensitive email content; API endpoint api.inboxfirewall.com may receive email data.
  • No CSP present (MV3 default is stricter but csp_present=false) combined with innerHTML DOM-XSS sink in content/ui.js.
  • New/low-profile developer (Neurear IT); no ratings, no install count, unverified publisher.
  • Generic Google privacy policy URL used — does not describe what this extension collects, retains, or shares.

Evidence

  • privacy_policy_generic store Privacy URL points to Google's own policy (scope_extension=false, data_collection=true, third_party_sharing=true) — scores +10.0 per v3.5 rule D.
  • dom_xss_sink crx content/ui.js: tt.innerHTML = content — DOM-XSS sink with no CSP; scored +2.0 under FIX B.
  • gmail_host_permission manifest Content script on https://mail.google.com/* allows reading email body; API endpoint may exfiltrate it.
  • no_installs_no_ratings store Install count empty, rating=0 — no social proof; unverified publisher.
  • no_cve_findings crx cve_findings_raw is empty; no known-vulnerable libraries detected.
  • recently_updated store Last updated April 28 2026, months_since_update=2; maintenance risk = 0.
  • no_threat_intel_hits api bad_host_hits, affiliate_hits, monetization_hits all empty; developer domain resolves and not throwaway.
  • mv3_no_csp_declared manifest MV3 with csp_present=false; no explicit CSP amplifies DOM-XSS risk in content script.

Permissions Breakdown

  • storage low Stores extension state locally; low direct harm.
  • activeTab low Scoped to user-initiated interaction only.
  • host:https://mail.google.com/* medium Content script on Gmail; reads email content for phishing detection.
  • host:https://api.inboxfirewall.com/* medium Extension backend API; email data may be sent here for analysis.
  • host:https://www.inboxfirewall.com/* low Marketing/info site; low risk on its own.

Pillar Scores

Permissions2.50
Reputation5.00
Network2.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA d60c36dc8b09…
Force block — not fired
Score recovered no
Elapsed 23.3s