Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Productive YouTube

jkibehpemolddpidiheemjpbkjjohdig
Risk Score
5.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 986
Rating 5.0
Last updated 2023-03-16 (39 months ago)
Manifest version MV3
CSP present ❌ no
Developer mehedi.2800@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Extension last updated 39 months ago — abandoned, unpatched against any future vulnerabilities.
  • Brand impersonation: 'YouTube' in name/description; dev is unverified gmail user, not Google.
  • webRequest permission can observe all YouTube network traffic including auth tokens.
  • No CSP present (MV3 mitigates somewhat but increases injection risk if code quality degrades).
  • Privacy policy fetched but not scoped to this extension and omits data retention disclosures.

Evidence

  • extreme_staleness store Last updated March 2023; 39 months since update triggers max maintenance score (+10.0).
  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['youtube']; developer is not Google/Alphabet.
  • free_webmail_dev_no_name manifest developer_email=mehedi.2800@gmail.com; developer_name empty; no verified business identity.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true — reputation discount applied but capped due to staleness.
  • tail_attack_surface api install_perm_anomaly: small_install_high_perm=true, tail_attack_surface=true; 986 installs + HIGH perm.
  • privacy_policy_not_scoped api Policy fetched; scope_extension=false, data_collection=false, retention=false, third_party_silence=true.
  • no_csp manifest content_security_policy=null; MV3 provides default but no explicit restrictive CSP declared.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — clean scan.

Permissions Breakdown

  • scripting medium Can inject JS into pages; scoped to youtube.com via host_permissions.
  • webRequest high Can observe all network requests on matched host; high capability even when scoped.
  • *://www.youtube.com/* medium Narrow host scope limits blast radius to YouTube only.

Pillar Scores

Permissions3.50
Reputation5.50
Network2.00
Webstore5.00
Maintenance10.00
Privacy6.00
Code Quality0.00
CVE Exposure0.00

Scoring History

v3.6 5.73 Medium review 2026-06-16
v3.4-rev 4.73 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA 6e6f19b7ab55…
Force block — not fired
Score recovered no
Elapsed 20.6s