Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VIDAVA

kppmfkiklcbbjegkbmfnohoidobhgimj
Risk Score
3.74
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Shopping
Installs 5
Rating
Last updated 2026-08-05
Manifest version MV3
CSP present ❌ no
Developer hello@vidava.ai
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • <all_urls> host permission + content scripts on every page including checkout/payment pages handles sensitive financial data.
  • Developer domain vidava.ai does not resolve — accountability gap for a financial AI extension.
  • Privacy policy admits data collection and third-party sharing but lacks retention disclosure.
  • innerHTML DOM sink in overlay JS is a XSS risk on pages where extension injects content.
  • Very low install count (5) with HIGH-tier permissions is a tail-attack-surface anomaly.

Evidence

  • host_permissions_all_urls manifest <all_urls> host permission combined with content_scripts on all URLs; runs on every site visited.
  • developer_domain_not_resolving api threat_intel: vidava.ai domain does not resolve — no live accountability surface for developer.
  • privacy_policy_no_retention api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • dom_xss_sink crx vidava-overlay.js: setBody(html){body.innerHTML=html} — unescaped variable into innerHTML, XSS risk.
  • install_perm_anomaly store 5 installs with high-tier permission (<all_urls>); small_install_high_perm=true.
  • js_external_hosts crx Extension contacts payjfhkpnsmyawugymfl.supabase.co, vidava.app, www.jsdelivr.com.
  • no_csp manifest MV3 extension with csp_present=false; dom_sink_innerhtml_userctrl finding elevated by FIX B.
  • unverified_new_developer store Not verified publisher, not featured, no ratings, domain non-resolving, 5 installs only.

Permissions Breakdown

  • storage low Used to persist extension state locally; low standalone risk.
  • activeTab medium Grants access to current tab on user action; scoped but pairs with <all_urls>.
  • tabs medium Can read tab URLs and metadata across browser; moderate surveillance surface.
  • <all_urls> (host_permission) high Content scripts injected on every site; reads checkout pages including payment data.

Pillar Scores

Permissions6.00
Reputation6.00
Network4.00
Webstore4.00
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:13
Listing SHA 0415da85ac1f…
Force block — not fired
Score recovered no
Elapsed