Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Crypto Tracker

jjfppgljnjgmkkbpkpbdbbdaleihgfnh
Risk Score
3.23
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 1,000
Rating 4.5
Last updated 2025-09-11 (9 months ago)
Manifest version MV3
CSP present ✅ yes
Developer kareem.ashraf.91@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • Developer uses free Gmail address with no verified business identity.
  • Extension is featured by Google but developer accountability is low (Gmail dev, no domain).
  • 3 external JS hosts (getbootstrap.com, github.com, webpack.js.org) referenced — verify these are CDN-only and not runtime code loads.
  • Small install base (1,000) limits blast radius but reduces vetting signal.

Evidence

  • no_declared_permissions manifest permissions[] and host_permissions[] are both empty; no HIGH/MEDIUM capabilities claimed.
  • free_webmail_developer store Developer email kareem.ashraf.91@gmail.com is free webmail; no verified business website.
  • generic_privacy_policy store Privacy URL points to Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true.
  • is_featured_by_google store Extension carries Google Featured badge, providing partial vetting signal despite Gmail dev identity.
  • csp_present_strict manifest CSP: script-src 'self'; object-src 'self'; — restrictive, no remote script sources allowed.
  • no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; 5/5 JS files scanned cleanly.
  • external_js_hosts crx 3 external hosts in CSP/references: getbootstrap.com, github.com, webpack.js.org — likely doc links only.
  • no_cve_findings crx cve_findings_raw is empty; no known-vulnerable libraries detected.

Pillar Scores

Permissions0.00
Reputation6.50
Network0.00
Webstore0.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA 004be2a96d70…
Force block — not fired
Score recovered no
Elapsed 16.6s