Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Netflix with Elapsed Time

knglmjodeneocikihhehegeifgabkjfa
Risk Score
4.26
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 5,000
Rating 4.6
Last updated 2026-06-09
Manifest version MV3
CSP present ✅ yes
Developer mynjcolo@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Netflix brand impersonation by unverified gmail developer — no confirmed ownership.
  • Privacy policy is Google's generic policy (scope_extension=false, admits data collection and 3rd-party sharing) — scores maximum privacy risk.
  • install_url_hijack=true: onInstalled opens a third-party URL.
  • DOM-XSS sink (innerHTML with variable) in vendor/overlay-widget.js could enable content injection on Netflix.
  • Free-webmail developer with no business domain; identity unverifiable.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'netflix'; developer is unverified gmail user.
  • install_url_hijack crx install_url_hijack=true; target=null. Opens 3rd-party URL on install.
  • generic_privacy_policy api Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true.
  • dom_xss_sink crx vendor/overlay-widget.js: innerHTML assigned from variable — DOM-XSS risk on netflix.com.
  • free_webmail_developer store Developer email mynjcolo@gmail.com; no business domain; identity unverifiable.
  • external_hosts crx JS contacts fonts.googleapis.com, ko-fi.com, storage.ko-fi.com — donation widget, low risk.
  • csp_present_mv3 manifest CSP script-src 'self'; object-src 'self' — strict, no remote script loading.
  • no_cve_findings crx cve_findings_raw empty; no bundled vulnerable libraries detected.

Permissions Breakdown

  • storage low Stores local extension state; no cross-origin data exposure.
  • tabs medium Can read tab URLs/titles; moderate info exposure.
  • host:https://www.netflix.com/* medium Scoped to Netflix only; content script injection on a major platform.

Pillar Scores

Permissions2.00
Reputation7.50
Network0.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA b487da6bc318…
Force block — not fired
Score recovered no
Elapsed 21.6s