Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Word Counter

kembaocngnfonkjfenhghpanlabelimn
Risk Score
5.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 81
Rating
Last updated 2023-05-03 (37 months ago)
Manifest version MV3
CSP present ❌ no
Developer sambillings8080@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch timed out — cannot confirm it covers this extension; treated as no valid policy.
  • Extension last updated 37+ months ago (zombie state); no maintenance or security patches.
  • Developer is anonymous gmail user with no verified identity or business presence.
  • Broad content_scripts on all HTTP/HTTPS sites despite minimal stated function (word count).
  • Verified publisher badge present but invariant 0c caps discount due to >18mo staleness.

Evidence

  • privacy_policy_fetch_failed api Privacy policy URL returned ReadTimeout; classified as fetched=false → +10.0 privacy pillar.
  • maintenance_zombie store months_since_update=37; >36mo bracket → pillar score 10.0.
  • anonymous_gmail_developer store developer_name empty, email sambillings8080@gmail.com; free-webmail dev, no business site.
  • verified_publisher_capped store verified_publisher=true but months_since_update>18 triggers v3.5 invariant 0c; discount capped at -1.0.
  • broad_content_scripts manifest content_scripts_matches: http://*/* and https://*/* — runs on every site the user visits.
  • no_cve_findings crx cve_findings_raw=[] and js_libraries_detected=[] — no known vulnerable libraries detected.
  • no_code_findings crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[] — no malicious code signals.
  • no_threat_intel_hits api bad_host_hits, affiliate_hits, monetization_hits all empty; developer_domain_info null.

Permissions Breakdown

  • activeTab low Grants access to active tab only on user interaction; low blast radius.
  • content_scripts http://*/* https://*/* medium Broad content script injection on all sites; elevates risk beyond activeTab alone.

Pillar Scores

Permissions1.30
Reputation6.50
Network0.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA ed929cf48d1c…
Force block — not fired
Score recovered no
Elapsed 18.1s