Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WTF

kcdlihaidnmkenhlnofkjfoachidbnif
Risk Score
3.72
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 211
Rating 4.0
Last updated 2024-12-08 (20 months ago)
Manifest version MV3
CSP present ❌ no
Developer wtf@marcosvr.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension at all (D-clause: +10.0 privacy).
  • Extension not updated for 20 months; stale codebase increases supply-chain risk.
  • Two innerHTML DOM-XSS sinks in popup.js and options.js with no CSP to mitigate.
  • No content_security_policy declared; MV3 default applies but innerHTML sinks unmitigated.
  • Low install count (211) limits blast radius, but stale + unscoped policy is concerning.

Evidence

  • privacy_policy_generic store Policy URL is Google's own account privacy page — scope_extension=false, data_collection=true, third_party_sharing=true. Triggers +10.0 privacy (D-clause).
  • maintenance_stale store Last updated December 8, 2024 — 20 months ago. Maintenance score +6.0 (12-24mo band).
  • dom_xss_sinks crx innerHTML assigned from variable in options.js and popup.js; no CSP present to block exploitation.
  • no_csp manifest content_security_policy is null; csp_present=false. DOM sinks unmitigated (FIX B: +2.0 code quality).
  • narrow_permissions manifest Only activeTab + storage; content_scripts scoped solely to web.whatsapp.com. Very low permission surface.
  • no_bad_hosts api threat_intel bad_host_hits, monetization_hits, affiliate_hits all empty. No threat-intel concerns.
  • unverified_publisher store verified_publisher=false, not featured. Developer domain resolves, not throwaway, no impersonation.
  • cve_none crx cve_findings_raw empty; js_libraries_detected empty. CVE pillar = 0.0.

Permissions Breakdown

  • activeTab low Only accesses current tab on user action; scoped to web.whatsapp.com.
  • storage low Local extension storage; no cross-origin data exposure.
  • content_scripts: https://web.whatsapp.com/* low Narrow single-domain scope; matches stated WhatsApp utility function.

Pillar Scores

Permissions0.60
Reputation5.00
Network0.00
Webstore0.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:50
Listing SHA a7302b34adfc…
Force block — not fired
Score recovered no
Elapsed