Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Simplified Twitter/X

kfopmjhmejbgomgeajemgpgpbckpoopg
Risk Score
4.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 3,000
Rating 4.7
Last updated 2025-07-12 (11 months ago)
Manifest version MV3
CSP present ❌ no
Developer chrome@brunolemos.org
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy — does not scope to this extension; admits data collection and third-party sharing.
  • brand_mention flags 'twitter' as impersonation; developer not confirmed owner, not verified publisher.
  • Dynamic script injection (script_src_dynamic) in inject.js with no CSP; injects bundled script.js into Twitter/X pages.
  • No CSP defined (MV3 default applies but no explicit restriction); dynamic script tag creation increases attack surface.
  • Last updated 11 months ago; moderate staleness with scripting capability on high-value social platform.

Evidence

  • privacy_policy_generic store Policy URL is Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true — D clause applies: +10.0.
  • brand_impersonation store brand_mention.is_impersonation=true for 'twitter'; confirmed_owner=false; not verified_publisher or featured: +2.0 reputation.
  • script_src_dynamic crx inject.js creates <script src=runtime.getURL('script.js')>; internal URL only, no external loading detected.
  • no_csp manifest content_security_policy is null; MV3 strict default applies but no explicit policy declared.
  • host_permissions_scoped manifest host_permissions limited to x.com, twitter.com, mobile.twitter.com — consistent with stated Twitter/X simplifier function.
  • no_bad_hosts_no_affiliates api threat_intel shows no bad_host_hits, affiliate_hits, or monetization_hits. js_external_hosts empty.
  • maintenance_staleness store 11 months since last update; falls in 6-12mo band: +3.5.
  • operator_cluster_clean api sibling_count=0; no related extensions under same fingerprint.

Permissions Breakdown

  • scripting medium Allows dynamic script injection; scoped to twitter/x.com only via host_permissions.
  • https://x.com/* medium Host access scoped narrowly to Twitter/X domains only.
  • https://twitter.com/* medium Host access scoped narrowly to Twitter/X domains only.
  • https://mobile.twitter.com/* low Narrow mobile sub-domain scope consistent with stated function.

Pillar Scores

Permissions2.00
Reputation6.00
Network0.00
Webstore2.00
Maintenance3.50
Privacy10.00
Code Quality3.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA 15d93f24a102…
Force block — not fired
Score recovered no
Elapsed 22.6s