Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

CSS Peek: Element Inspector

kfmdddceeniapmonignkaflhpidamhig
Risk Score
4.22
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 352
Rating 5.0
Last updated 2026-02-22 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer daniel.ivanov.delchev@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope to this extension at all; admits data collection and 3rd-party sharing.
  • Content script injected on <all_urls> gives broad per-page DOM access on every site visited.
  • Gmail developer with no business domain; identity unverifiable.
  • No CSP declared (MV3 default applies, but no explicit policy recorded) alongside broad content-script reach.
  • Libraries detected (react, lodash, jszip) at unknown versions; CVE exposure unverifiable.

Evidence

  • content_scripts_matches=<all_urls> manifest Content script injected on every URL; broad DOM read capability despite narrow declared permissions.
  • privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • developer_email_gmail store Developer uses free Gmail address with no registered business domain; identity unverifiable.
  • is_featured_by_google=true store Google Featured badge provides partial trust signal; applied -2.0 reputation discount.
  • js_libraries_unknown_version crx react, react-dom, lodash, lodash-es, jszip detected via sourcemap; versions unknown — CVE check inconclusive.
  • no_bad_hosts_no_affiliate api threat_intel shows no bad/affiliate/monetization hits; external hosts limited to github.com, react.dev.
  • obfuscation_score=0.0_code_findings_empty crx No obfuscation detected; code_findings_raw empty; code quality pillar scored 0.
  • months_since_update=4 store Updated Feb 2026; 4 months ago — maintenance penalty +1.5 (3-6 month band).

Permissions Breakdown

  • activeTab low Scoped to user-activated tab; minimal reach without broad host access.
  • downloads medium Can initiate file downloads; enables asset/export feature but adds surface.
  • storage low Local settings persistence only; no network exfil path by itself.
  • content_scripts:<all_urls> high Injects JS into every page the user visits; broad content-script reach.

Pillar Scores

Permissions4.50
Reputation6.50
Network2.00
Webstore1.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA 9973af662d8c…
Force block — not fired
Score recovered no
Elapsed 21.3s