Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Quality Enhancer • AI 4K Upscale, Sharpen, Light, Gamma & Color Fix

kjhigpfcihnpjchpfnboofeecckigbmb
Risk Score
4.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 20,000
Rating 4.7
Last updated 2026-06-05
Manifest version MV3
CSP present ❌ no
Developer john.webber.dev@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail) with no verified business identity; no dev name listed.
  • <all_urls> host permission + scripting on all pages enables broad data access on every site visited.
  • No CSP on MV3 extension with external JS hosts including ipinfo.io (IP geolocation) and saasminded.dev.
  • install_url_hijack and uninstall_url_hijack both true; redirect targets not captured but pattern is concerning.
  • innerHTML DOM-XSS sink in content.js with no CSP mitigates inline-script injection risk.

Evidence

  • free_webmail_dev_no_name store dev email john.webber.dev@gmail.com; developer_name empty; no verified business domain.
  • host_permissions_all_urls_scripting manifest host_permissions=[<all_urls>] + scripting + content_scripts on <all_urls>; runs on every page.
  • no_csp_mv3 crx content_security_policy is null; no CSP despite 6 external JS hosts contacted.
  • install_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets not captured.
  • external_hosts_ipinfo_saasminded crx Contacts ipinfo.io (IP geo lookup) and saasminded.dev; purpose of geo lookup unexplained.
  • dom_sink_innerhtml_userctrl crx content.js assigns variable to innerHTML with no CSP; DOM-XSS risk.
  • verified_publisher store verified_publisher=true with own domain videoqualityenhancer.app; partially offsets reputation risk.
  • privacy_policy_adequate api Policy fetched, scoped to extension, data_collection+retention disclosed; third_party_silence=true +1.

Permissions Breakdown

  • storage low Stores extension settings locally; low standalone risk.
  • scripting high Programmatic script injection; high capability when paired with <all_urls>.
  • offscreen low Offscreen document for media processing; low risk in isolation.
  • <all_urls> high Broad host access; content scripts on every site visited amplifies all other permissions.

Pillar Scores

Permissions6.50
Reputation5.50
Network4.50
Webstore5.50
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA a2849e1456f9…
Force block — not fired
Score recovered no
Elapsed 27.4s