Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WPS PDF - Read, Edit, Fill, Convert, and AI Chat PDF with Ease

kdpelmjpfafjppnhbloffcjpeomlnpah
Risk Score
4.45
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 6,000,000
Rating 4.5
Last updated 2026-07-30 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer feedback@wps.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • nativeMessaging with unrecognized publisher: extension can bridge to OS-level native app with no publisher sanity check.
  • cookies + scripting + <all_urls> + webRequest: full read/write/intercept of all sites and sessions.
  • Privacy policy not scoped to extension; fetched policy admits data collection and third-party sharing (+10 privacy).
  • No CSP (MV3 strict default applies but csp_present=false noted); new Function() in background.js raises code-quality concern.
  • AI category processing page content at scale; 7M installs amplifies blast radius of any compromise or policy change.

Evidence

  • nativeMessaging + publisher_recognized=false crx Extension uses nativeMessaging but native_messaging_check.publisher_recognized is false; adds +3.0 permissions.
  • cookies + <all_urls> manifest HIGH permission cookies paired with broad host access triggers x1.2 amplifier on permissions pillar.
  • privacy_policy scope_extension=false, data_collection=true, third_party_sharing=true api Policy fetched but not scoped to this extension, admits data collection and third-party sharing → Privacy pillar +10.0.
  • uninstall_url_hijack=true crx chrome.runtime.setUninstallURL() redirects user on uninstall; adds +3.0 webstore signal.
  • function_constructor in background.js crx new Function() in background script is a code-quality risk signal (+2.5 code quality).
  • is_featured_by_google=true, rating=4.5 store Google Featured badge and high rating provide partial trust signal; reputation floor applied.
  • looks_throwaway=true on wps.com api developer_domain_info.looks_throwaway=true despite wps.com resolving; adds +1.5 webstore.
  • AI extension processing page content at 7M installs store +2.5 webstore for AI/Gen-AI category processing page content; +1.0 installs>1M; -0.5 popularity-trust.

Permissions Breakdown

  • webRequest high Intercept/observe all network requests; paired with <all_urls> is maximum-reach.
  • webNavigation medium Observe all page navigations across every site visited.
  • storage low Local extension data storage; standard low-risk capability.
  • tabs medium Read URL, title, and status of all open tabs.
  • nativeMessaging high Communicate with host-OS native app; publisher_recognized==false amplifies risk.
  • declarativeNetRequest medium Modify/block network requests; lower risk than webRequestBlocking alone.
  • gcm medium Receive push messages from developer servers silently.
  • cookies high Read/write cookies on all URLs; combined with <all_urls> = critical surface.
  • notifications low Display desktop notifications; limited direct data-access risk.
  • scripting high Inject arbitrary JS into any page; paired with <all_urls> is very high risk.
  • <all_urls> (host_permissions) high Broad host access amplifies every HIGH permission by x1.2 multiplier.

Pillar Scores

Permissions9.00
Reputation4.50
Network6.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

%27fsssiedxa sssiedx 6.11 High review 2026-08-13
fsssiedxa<sssiedx 6.22 High block 2026-08-13
%76%33%2E%36%39%36%32%39%22%28%29%3B%7D%5D%39%35%39%32 6.44 High block 2026-08-05
dfb__${98991*97996}__::.x 6.09 High review 2026-08-05
v3.6&n926860=v956300 6.24 High review 2026-08-05
<fsssiedxf"sssiedx 4.59 Medium block 2026-08-04
<fsssiedxf$"sssiedx 5.95 Medium review 2026-08-04
<fsssiedx{$'sssiedx 6.17 High block 2026-08-04
xx pfsssiedxisssiedx 4.43 Medium block 2026-08-04
"fsssiedxifdsaxax><!--></ScRiPt>asddsssiedx 6.06 High block 2026-08-04
'fsssiedxi$'sssiedx 4.41 Medium review 2026-08-04
&#x27;fsssiedxi$'sssiedx 4.64 Medium review 2026-08-04
&#x22;fsssiedxi$'sssiedx 4.54 Medium review 2026-08-04
fsssiedxi<sssiedx 6.05 High block 2026-08-04
<fsssiedxi&#x27;sssiedx 6.11 High review 2026-08-04
<fsssiedxa xx psssiedx 4.45 Medium review 2026-08-04
<fsssiedxa$"sssiedx 6.06 High review 2026-08-04
v3.69940/"();}]9994 6.18 High review 2026-07-29
v3.6"onmouseover=fTnz(98562)" 6.05 High review 2026-07-29
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 6.19 High review 2026-07-29
<%={{={@{#{${dfb}}%> 4.50 Medium block 2026-07-29
dfb[[${98991*97996}]]xca 6.12 High block 2026-07-29
dfb{{98991*97996}}xca 6.39 High block 2026-07-29
v3.69566888< 6.04 High block 2026-07-29
fsssiedx<sssiedx 5.86 Medium review 2026-07-28
<fsssiedx{ xx psssiedx 6.07 High block 2026-07-28
<fsssiedx{$"sssiedx 6.11 High block 2026-07-28
<fsssiedxf'sssiedx 6.07 High review 2026-07-28
fsssiedxxfdsaxax><!--></ScRiPt>asddsssiedx 6.05 High review 2026-07-28
sssieddrubricxsx 6.01 High block 2026-07-28
v3.6 4.45 Medium review 2026-06-15
v3.4-rev 5.87 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 07:47
Listing SHA 9f9dd978f859…
Force block — not fired
Score recovered no
Elapsed 32.3s