Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Otto: Pomodoro timer & Website Blocker. Block sites, Focus mindfully

jbojhemhnilgooplglkfoheddemkodld
Risk Score
4.06
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 60,000
Rating 4.7
Last updated 2026-05-08 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer jbnj@ottoapp.me
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing true — worst-case privacy posture (score +10.0).
  • No CSP declared (MV3); innerHTML sinks in 8 files including contentScript running on <all_urls> elevate DOM-XSS risk.
  • scripting + <all_urls> content_scripts allow arbitrary JS injection on every visited site.
  • Privacy policy does not scope to this extension despite 60k users and broad host access.
  • developer_name absent; identity anchored only to ottoapp.me email despite verified-publisher badge.

Evidence

  • privacy_policy_scope_extension_false_with_collection_and_sharing api Policy fetched, length 101666; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5-D).
  • no_csp_mv3 manifest content_security_policy is null; no CSP on MV3. innerHTML sinks in 8 JS files elevate XSS risk without mitigation.
  • dom_sink_innerhtml_userctrl_multi crx 8 files contain innerHTML sinks (blockpage, contentScript, fanalytics, settingsPage, onboarding, autoblock, permaBlockpage, popup).
  • function_constructor crx new Function() in background.bundle.js; standard React globalThis shim but still a dynamic code eval path.
  • scripting_plus_all_urls manifest scripting permission + <all_urls> host + content_scripts on all URLs = full page JS injection capability.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; reputation floor 2.0 applied.
  • threat_intel_clean api No bad_host_hits, affiliate_hits, monetization_hits, or review red flags detected.
  • maintenance_current store Last updated May 8 2026; months_since_update=1 → maintenance score 0.0.

Permissions Breakdown

  • action low UI toolbar button — no data access.
  • alarms low Timer scheduling, matches stated Pomodoro function.
  • storage low Local preference storage.
  • declarativeNetRequest medium URL blocking; matches stated website-blocker function.
  • tabs medium Can read tab URLs/titles across all tabs.
  • notifications low User-facing Pomodoro alerts.
  • offscreen low Background audio/timer use; low direct risk.
  • unlimitedStorage low Extended local storage quota.
  • scripting high Arbitrary JS injection into pages; broad with <all_urls>.
  • activeTab low Scoped to user-activated tab only.
  • <all_urls> (host) high Content scripts and scripting run on every site; high reach.

Pillar Scores

Permissions5.80
Reputation2.00
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA 49e73a335194…
Force block — not fired
Score recovered no
Elapsed 32.9s