Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Control for Instagram

jlebjkamppjaeoiinkjkgmecoahlefka
Risk Score
3.64
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 20,000
Rating 4.4
Last updated 2026-04-30 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer mail@david-schulte.de
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing (Privacy pillar maxed at 10.0).
  • Brand impersonation: extension name/function references Instagram without confirmed owner relationship.
  • No developer display name on listing; only email identity available.
  • No CSP present (MV3 mitigates but content-script on Instagram.com with no policy is residual risk).
  • Generic policy explicitly discloses third-party sharing without extension-specific scope.

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google account policy, scope_extension=false, third_party_sharing=true.
  • brand_impersonation store brand_mention.is_impersonation=true; Instagram brand referenced, confirmed_owner=false.
  • no_developer_name store developer_name is empty string; only email mail@david-schulte.de identifies dev.
  • verified_publisher store verified_publisher=true; domain david-schulte.de resolves, not throwaway.
  • content_script_scope manifest content_scripts_matches limited to *://*.instagram.com/* — matches stated single-site function.
  • no_cve_no_bad_hosts crx cve_findings_raw empty, bad_host_hits empty, affiliate_hits empty, monetization_hits empty.
  • clean_code crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty.
  • recently_updated store months_since_update=2; maintenance risk is minimal.

Permissions Breakdown

  • storage low Stores local extension settings; no data exfil path on its own.
  • content_scripts *://*.instagram.com/* medium Injects JS into all Instagram pages; scoped to single domain, matches stated function.

Pillar Scores

Permissions1.30
Reputation5.00
Network0.00
Webstore3.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA 2a74e07d7a45…
Force block — not fired
Score recovered no
Elapsed 19.3s