Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

The Education District

jghlbgpehejkbenneehiialadabidfpb
Risk Score
6.07
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Other
Installs 988
Rating 3.7
Last updated 2023-04-12 (39 months ago)
Manifest version MV3
CSP present ❌ no
Developer tejedor@virtway.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • nativeMessaging with unrecognized publisher gives OS-level code execution surface on every user machine.
  • Extension last updated 39 months ago — zombie risk, no security patches since April 2023.
  • file:///* host permission exposes all local files to extension content scripts.
  • Privacy policy is a generic iubenda template: scope_extension==false, no collection or retention disclosure.
  • Small install base (988) with HIGH-tier permissions (install_perm_anomaly) raises tail-attack-surface concern.

Evidence

  • nativeMessaging + publisher_recognized==false manifest nativeMessaging declared; native_messaging_check.publisher_recognized=false → +3.0 permissions.
  • file:///* host permission manifest Broad local filesystem access granted via host_permissions and content_scripts_matches.
  • months_since_update=39 (>36mo) store Last updated April 2023; maintenance pillar = 10.0 (zombie). No changelog visible.
  • install_url_hijack=true crx onInstalled opens third-party URL; +2.0 webstore per install-URL-hijack rule.
  • no CSP (csp_present=false, MV3) manifest MV3 has strict default; no additional network penalty but inline execution unguarded.
  • privacy policy generic iubenda api scope_extension=false, data_collection=false, third_party_silence=true → privacy pillar 9.0.
  • install_perm_anomaly api small_install_high_perm=true, tail_attack_surface=true; 988 installs with nativeMessaging.
  • verified_publisher=true, developer domain resolves store virtway.com resolves, verified publisher; reputation discount applied but capped due to staleness >18mo.

Permissions Breakdown

  • nativeMessaging high Allows arbitrary communication with host OS apps; publisher_recognized==false adds +3.0 native-messaging penalty.
  • tabs medium Exposes tab URLs and metadata across browsing session.
  • https://*.public.theeducationdistrict.com/* low Scoped to own service domain; limited blast radius.
  • https://*.cms.theeducationdistrict.com/* low Scoped to own CMS domain; limited blast radius.
  • file://*/* high Access to all local files on the filesystem is a high-impact capability.

Pillar Scores

Permissions6.50
Reputation3.50
Network2.00
Webstore4.50
Maintenance10.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-15 14:17
Listing SHA 406648d57c3f…
Force block — not fired
Score recovered no
Elapsed