Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Anywhere stickers - simple sticky notes

joiomjhjkacipamidllnbicjcdmoheha
Risk Score
3.55
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 20,000
Rating 4.4
Last updated 2026-03-09 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer anywhere.stickers@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; data practices undisclosed.
  • Content script on <all_urls>: runs on every page, broad reach for a simple sticky-notes tool.
  • Free-webmail developer (gmail.com), no verified business identity or domain.
  • innerHTML written from variable in onScreenNotificator.js with no CSP — DOM-XSS risk.
  • Google Featured badge partially offsets reputation gap but dev accountability remains low.

Evidence

  • content_scripts_broad manifest content_scripts matches <all_urls> — extension runs on every page.
  • privacy_policy_generic store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_webmail store Developer email anywhere.stickers@gmail.com — free webmail, no verified business.
  • dom_xss_sink crx onScreenNotificator.js: innerHTML assigned from variable; no CSP to mitigate.
  • featured_by_google store Extension carries Google Featured badge — partial trust signal.
  • no_bad_hosts api threat_intel shows empty bad_host_hits, affiliate_hits, monetization_hits.
  • recently_updated store Last updated March 9, 2026 — 3 months ago; maintenance risk minimal.
  • no_cves crx cve_findings_raw is empty; no vulnerable bundled libraries detected.

Permissions Breakdown

  • activeTab low Grants access only to the currently active tab on user action.
  • storage low Local key-value storage for saving sticky note data.
  • scripting medium Can inject scripts into pages; paired with content_scripts <all_urls> raises reach.
  • content_scripts <all_urls> high Content script runs on every page visited, broad reach for a notes tool.

Pillar Scores

Permissions3.30
Reputation6.50
Network0.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA 347f64c8f82a…
Force block — not fired
Score recovered no
Elapsed 23.3s