Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

daily.dev | Where developers discover what's next

jlmpjdjjbgclbocgajdjefcidcncaied
Risk Score
4.17
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 400,000
Rating 4.8
Last updated 2026-08-18
Manifest version MV3
CSP present ✅ yes
Developer hi@daily.dev
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true: policy admits broad collection without scoping to this extension.
  • Dynamic script injection (script_src_dynamic) in 3 bundle files — remote code loading risk even with strict CSP.
  • NewTab override with 400K installs gives high reach; every user's new tab is controlled by this extension.
  • No developer name listed; developer_email domain (daily.dev) resolves but no verified-publisher badge.
  • Uninstall URL hijack flag set (uninstall_url_target null but signal is true); potential post-removal tracking.

Evidence

  • privacy_policy_admits_3p_sharing_no_scope api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
  • script_src_dynamic_x3 crx 3 bundle files create dynamic <script> elements; counts as script_src_dynamic → +3.0 code quality.
  • dom_sink_innerhtml_x2 crx 2 files with innerHTML from variable; CSP present so +0.5 each, but csp_present mitigates FIX B escalation.
  • newtab_override manifest chrome_url_overrides.newtab=index.html; +2.0 webstore (NewTab override). Category-matched discount applied.
  • uninstall_url_hijack store uninstall_url_hijack=true (target null); +3.0 webstore per rubric, but target unknown — applied conservatively.
  • featured_by_google store is_featured_by_google=true → -2.0 reputation (Featured badge).
  • no_developer_name store developer_name is empty string → +1.0 reputation.
  • no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.

Permissions Breakdown

  • scripting medium Allows dynamic script injection into pages; medium risk when scoped to host_permissions only.
  • host_permissions: https://daily.dev/, https://*.daily.dev/, https://dailynow.co/, https://*.dailynow.co/ low Scoped to developer-owned domains only; narrow blast radius.
  • chrome_url_overrides: newtab medium Replaces every new tab; high reach but category-matched (NewTab news reader).
  • content_scripts: https://*.daily.dev/*, https://daily.dev/* low Content scripts scoped to developer-owned domain only.

Pillar Scores

Permissions2.50
Reputation3.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Scoring History

&#x22;fsssiedxa sssiedx 2.86 Low review 2026-08-20
fsssiedxa$"sssiedx 2.63 Low review 2026-08-20
<fsssiedxa xx psssiedx 4.26 Medium block 2026-08-01
<fsssiedxa 4.22 Medium review 2026-08-01
<fsssiedxa$'sssiedx 4.43 Medium review 2026-08-01
<fsssiedxa'sssiedx 4.49 Medium review 2026-08-01
<fsssiedxa$"sssiedx 4.36 Medium review 2026-08-01
xx pfsssiedxa sssiedx 4.23 Medium review 2026-08-01
"fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.47 Medium review 2026-08-01
"fsssiedxa$"sssiedx 4.44 Medium review 2026-08-01
%27fsssiedxa sssiedx 4.73 Medium review 2026-08-01
&#x22;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.25 Medium review 2026-08-01
4.45 Medium review 2026-08-01
fsssiedxa<sssiedx 4.47 Medium review 2026-08-01
fsssiedxa'sssiedx 4.55 Medium review 2026-07-30
sssieddrubricxsx 4.65 Medium review 2026-07-30
v3.6 4.17 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA e6310466e2ab…
Force block — not fired
Score recovered no
Elapsed 31.9s