Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Anti phising safer browsing for chrome

jkokgpghakemlglpcdajghjjgliaamgc
Risk Score
4.34
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 7,000
Rating 4.5
Last updated 2025-02-18 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer thomas.schmitt@browserguard.net
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but admits data collection + third-party sharing without extension-specific scope — rated maximum privacy risk.
  • Uninstall URL hijack to browserguard.net; install redirect also active — behavioural monetization signals.
  • Content scripts injected on <all_urls> with innerHTML DOM-XSS sinks and no CSP — elevated code-quality risk.
  • No developer display name despite verified-publisher badge; 18-month stale cap limits verified-publisher discount.
  • Privacy policy scope_extension=false with data_collection+third_party_sharing=true triggers D-clause max privacy penalty.

Evidence

  • privacy_policy_D_clause api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D-clause).
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL to https://browserguard.net/uninstall → +3.0 webstore.
  • install_url_hijack crx onInstalled opens https://browserguard.net/install → +2.0 webstore.
  • dom_sink_innerhtml_no_csp crx Two innerHTML sinks found, csp_present=false → dom_sink score elevated to +2.0 per FIX B.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true, has_high_tier_permission with 7k installs → +1.0 webstore.
  • no_developer_name store developer_name is empty string; verified_publisher=true caps reputation discount per 0c (months_since_update=18).
  • maintenance_stale store months_since_update=18 → 12-24mo band → +6.0 maintenance.
  • host_permissions_all_urls manifest <all_urls> host + content_scripts on all URLs; category=Security gives justified-broad discount applied.

Permissions Breakdown

  • declarativeNetRequest medium Allows blocking/redirecting network requests; core to stated security function.
  • storage low Local key-value storage only; minimal risk.
  • <all_urls> (host_permission) high Full access to every site the user visits; content scripts injected on all URLs.
  • content_scripts <all_urls> high Scripts run on every page; DOM manipulation possible site-wide.

Pillar Scores

Permissions4.50
Reputation4.50
Network3.50
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:53
Listing SHA 43343de206e7…
Force block — not fired
Score recovered no
Elapsed