Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Pie Adblock - A Powerful Free Ad Blocker

jpkfgepcmmchgfbjblnodjhldacghenp
Risk Score
3.92
Risk Level: Low
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category Adblock
Installs 2,000,000
Rating 4.9
Last updated 2026-08-23
Manifest version MV3
CSP present ❌ no
Developer extensions@pie.org
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
  • eval() of variable in twitch userscript + management permission creates elevated code-exec risk.
  • management permission allows enumeration and control of other installed extensions.
  • Privacy policy discloses third-party data sharing; no isolation to extension context concerns.
  • 11 distinct external JS hosts including retail/streaming domains; broad network surface for adblock category.

Evidence

  • verified_publisher + featured store Verified publisher badge and featured by Google; reputation floor applied at 2.0.
  • eval_user_input crx eval(workerString) in twitch-vaft-userscript-v2.js — dynamic eval of variable.
  • function_constructor x3 crx new Function('return this') pattern in 3 content scripts; low-severity globalThis polyfill pattern.
  • management permission manifest management permission declared; can enumerate/disable other extensions — high risk not fully justified by adblock.
  • privacy_policy third_party_sharing api Policy fetched, scoped, data_collection+third_party_sharing=true, retention=true. +1.0 for sharing.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() called; target URL not captured for verification.
  • js_external_hosts x11 crx 11 distinct external hosts including retail (amazon, asos, acehardware) and twitch.tv — expected for affiliate adblock.
  • cve_findings_raw empty crx No CVEs detected in bundled libraries (jquery 3.7.1, react 16.13.1). CVE pillar = 0.

Permissions Breakdown

  • alarms low Scheduling only; minimal risk.
  • cookies high Access to all cookies; paired with <all_urls> amplifies risk, but justified for adblock.
  • tabs medium Can read tab URLs and metadata.
  • storage low Local extension data only.
  • scripting high Arbitrary script injection into pages; core to adblock function.
  • webNavigation medium Monitors navigation events across all tabs.
  • unlimitedStorage low Storage quota only; no data access risk.
  • declarativeNetRequestWithHostAccess high Intercept/block network requests broadly; expected for adblock.
  • declarativeNetRequestFeedback low Read-only feedback on matched rules.
  • webRequest high Observe all network requests; core adblock capability.
  • management high Can enumerate/manage other extensions; elevated risk.
  • offscreen low Off-screen document; limited risk surface.
  • <all_urls> (host) high Broad host access enabling script/request interception on every site.

Pillar Scores

Permissions7.50
Reputation2.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy1.00
Code Quality3.50
CVE Exposure0.00

Scoring History

sssiednbfcebeb8dp727562726963xsx 5.21 Medium block 2026-08-30
<fsssiedx{$"sssiedx 5.06 Medium block 2026-08-19
%27fsssiedxn"sssiedx 4.27 Medium block 2026-08-19
&#x22;fsssiedxn&#x27;sssiedx 4.27 Medium block 2026-08-19
fsssiedxn<sssiedx 4.54 Medium block 2026-08-19
fsssiedx<sssiedx 4.32 Medium block 2026-08-19
<fsssiedxa&#x22;sssiedx 4.76 Medium block 2026-08-18
<fsssiedxa$'sssiedx 3.92 Low block 2026-08-18
<fsssiedxa&#x27;sssiedx 4.65 Medium block 2026-08-18
<fsssiedxa xx psssiedx 4.22 Medium block 2026-08-18
<fsssiedxa$"sssiedx 4.42 Medium block 2026-08-18
xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.71 Medium block 2026-08-18
%27fsssiedxa"sssiedx 4.14 Medium block 2026-08-18
&#x27;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.37 Medium block 2026-08-18
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.38 Medium block 2026-08-18
fsssiedxa<sssiedx 3.61 Low block 2026-08-18
fsssiedxa"sssiedx 5.22 Medium block 2026-08-05
sssieddrubricxsx 3.95 Low block 2026-08-05
v3.6 3.92 Low block 2026-06-16
v3.4-rev 2.41 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA e582807b234b…
Force block 🚫 fired
Score recovered no
Elapsed 29.2s