Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Image Downloader - Image Search

jfafkhnopckjfmnpekbmpmghhdlijaja
Risk Score
4.93
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 50,000
Rating 4.6
Last updated 2025-01-19 (20 months ago)
Manifest version MV3
CSP present ✅ yes
Developer thinhkifaresduc@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail developer (gmail) with no verified business identity raises accountability gap.
  • Privacy policy hosted on Google Sites, not scoped to this extension; data_collection=true, retention undisclosed.
  • webRequest + <all_urls> content scripts enable broad passive observation of all browsing traffic.
  • innerHTML sinks in popup.js and contentScript.js create DOM-XSS exposure on every visited page.
  • Stale 17 months; no verified publisher; policy admits data collection without scope or retention terms.

Evidence

  • free_webmail_developer store Developer email is thinhkifaresduc@gmail.com — no verified business domain.
  • broad_host_permissions manifest <all_urls> host_permissions + content_scripts_matches on all URLs; paired with webRequest.
  • privacy_policy_not_scoped api Policy on Google Sites; scope_extension=false, data_collection=true, retention=false, third_party_silence=true.
  • dom_xss_sinks crx innerHTML assigned from variable in both popup.js and contentScript.js (React internals pattern but present in content script).
  • maintenance_stale store Last updated January 19 2025; 17 months since update — approaching high-risk threshold.
  • featured_by_google store is_featured_by_google=true provides moderate trust signal.
  • no_bad_hosts_or_affiliates api bad_host_hits, affiliate_hits, monetization_hits all empty; 1 external host reactjs.org (CDN reference only).
  • cve_clean crx cve_findings_raw is empty; no bundled vulnerable libraries detected.

Permissions Breakdown

  • storage low Saves extension settings locally.
  • activeTab low Temporary access to current tab on user action.
  • scripting medium Can inject scripts into pages; combined with <all_urls> broadens reach.
  • downloads medium Core to stated function; can download arbitrary files.
  • webRequest high Can observe all HTTP requests across all URLs.
  • declarativeNetRequest medium Can block/redirect network requests declaratively.
  • sidePanel low UI surface only; low standalone risk.
  • <all_urls> high Broad host access enables content scripts and requests on every site.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.00
Webstore1.00
Maintenance6.00
Privacy9.00
Code Quality1.00
CVE Exposure0.00

Scoring History

fsssiedxn3a14b685zan3a14b685zsssiedx 5.44 Medium review 2026-09-15
sssiedn3c30cfa4dp727562726963xsx 4.84 Medium review 2026-09-15
v3.6 4.93 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA 989acd4aaade…
Force block — not fired
Score recovered no
Elapsed 24.1s