Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Volume Master

jghecgabfgfdldnmbfkhmffcabddioke
Risk Score
3.74
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Accessibility
Installs 7,000,000
Rating 4.8
Last updated 2025-04-14 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@petasittek.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false and data_collection=true — policy admits collection without scoping to this extension.
  • install_url_hijack and uninstall_url_hijack flags set; install/uninstall redirect behavior warrants inspection.
  • No CSP present (MV3 default enforced, but csp_present=false increases DOM-XSS impact from innerHTML sink).
  • Maintenance: 14 months since last update (6-12mo band) adds moderate staleness risk at 7M installs.
  • Developer name empty; identity relies solely on email domain petasittek.com.

Evidence

  • verified_publisher + featured store Extension is verified publisher and featured by Google; reputation floor applied at 2.0.
  • privacy_policy_scope_extension=false + data_collection=true api Policy fetched, scope_extension false, data_collection true, third_party_sharing false → privacy pillar +9.0.
  • install_url_hijack + uninstall_url_hijack crx Both install and uninstall URL hijack flags true; targets null but behavior present → +2.0 webstore.
  • dom_sink_innerhtml_userctrl + no CSP crx innerHTML sink in popup.js; csp_present=false triggers FIX B → code quality +2.0.
  • installs > 1M store 7M installs: +1.0+1.0+0.5 install tiers; -0.5 popularity-as-trust (rating 4.8 ≥ 4.0).
  • maintenance 14 months store 14 months since update falls in 12-24mo band → +6.0 maintenance score.
  • no CSP + MV3 manifest MV3 enforces strict default; v2 calibration +2.0 network penalty for MV2 not applicable here.
  • threat_intel clean api No bad_host_hits, affiliate_hits, monetization_hits, or search engines. Developer domain resolves.

Permissions Breakdown

  • activeTab low Grants access to current tab only on user action; limited scope.
  • offscreen low Creates offscreen document for audio processing; expected for volume control.
  • tabCapture medium Can capture tab audio/video streams; core function for volume boosting but sensitive.
  • tabs medium Access to tab metadata (URLs, titles); broader than strictly needed.
  • storage low Local settings persistence; standard low-risk use.

Pillar Scores

Permissions2.30
Reputation2.00
Network0.00
Webstore4.50
Maintenance6.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA 01236fb3ca9f…
Force block — not fired
Score recovered no
Elapsed 26.1s