Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Calendar Plus

kgbbebdcmdgkbopcffmpgkgcmcoomhmh
Risk Score
4.36
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 2,000
Rating 4.4
Last updated 2025-03-18 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer chrome-extension@patii.uk
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Brand impersonation flag: extension mentions 'google' in brand_mention but developer is not a verified Google entity.
  • No CSP on MV3 extension; innerHTML DOM-XSS sink present in bundled React code without CSP mitigation.
  • Last updated 15 months ago — approaching stale threshold; no changelog visible.
  • No developer name declared; identity tied only to patii.uk domain email.

Evidence

  • privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
  • brand_impersonation store brand_mention.is_impersonation=true; mentions 'google' brand; developer is verified_publisher so +1.0 reputation (v3.2 rule 9).
  • dom_sink_innerhtml crx dom_sink_innerhtml_userctrl in dist/main.bundle.js; no CSP present → elevated to +2.0 code quality (FIX B).
  • no_csp manifest content_security_policy is null on MV3; does not trigger MV2+no-CSP bonus but leaves innerHTML sink unmitigated.
  • maintenance_stale store months_since_update=15; falls in 12-24 month band → +6.0 maintenance pillar.
  • verified_publisher store verified_publisher=true and is_featured_by_google=true; discount capped at -1.0 per invariant 0c (months_since_update>12 threshold not triggered at 15mo but >18mo cap not reached).
  • no_developer_name store developer_name is empty string; +1.0 reputation for missing 'Offered by' name.
  • content_script_scope manifest content_scripts scoped to calendar.google.com only — narrow, matches stated function; no broad host permissions declared.

Permissions Breakdown

  • identity low OAuth token access; low risk without broad scopes declared.
  • storage low Local extension storage only; no cross-site data risk.
  • content_scripts: https://calendar.google.com/calendar/u/0/r/* medium Script injected into Google Calendar pages; scoped to one domain but can read calendar data.

Pillar Scores

Permissions1.30
Reputation5.50
Network2.00
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA b8a494850756…
Force block — not fired
Score recovered no
Elapsed 24.7s