Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tab Suspender

laameccjpleogmfhilmffpdbiibgbekf
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 20,000
Rating 3.6
Last updated 2025-01-22 (19 months ago)
Manifest version MV3
CSP present ❌ no
Developer tayloreolivian4@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • new Function() constructor present in all 6 JS files — dynamic code execution risk with broad host access.
  • Privacy policy is only 16 chars, not scoped to this extension, and data_collection=false with no retention info — effectively inadequate.
  • Free-webmail developer (gmail) with no developer name; verified/featured discounts partially offset but not eliminated.
  • Broad host permissions (http://*/*, https://*/*) + scripting allow arbitrary content injection on every site.
  • 19 months since last update; v3.5 invariant 0c caps verified-publisher discount due to stale update.

Evidence

  • free_webmail_developer store Developer email tayloreolivian4@gmail.com is free webmail; no developer name provided.
  • verified_publisher_featured store Extension has verified_publisher=true and is_featured_by_google=true; discount capped at -1.0 due to stale 19mo.
  • broad_host_permissions manifest host_permissions include http://*/* and https://*/* combined with scripting permission.
  • function_constructor_all_files crx new Function() constructor found in all 6 scanned JS files; potential dynamic code execution surface.
  • privacy_policy_inadequate api Policy fetched but only 16 chars, scope_extension=false, data_collection=false, third_party_silence=true.
  • stale_update store Last updated January 22, 2025; 19 months since update triggers maintenance risk.
  • no_csp manifest content_security_policy is null; no CSP declared on MV3 extension.
  • cve_clean crx cve_findings_raw is empty; no known CVEs in bundled libraries.

Permissions Breakdown

  • storage low Standard local state persistence; low risk.
  • unlimitedStorage low Allows larger local storage quota; minimal risk.
  • tabs medium Can read tab URLs/titles across all open tabs.
  • favicon low Read-only favicon access; low risk.
  • scripting high Combined with <all_urls> host perms, can inject JS into any page.
  • contextMenus low UI surface addition only; low risk.
  • system.memory low Read-only system memory info; low risk.
  • http://*/* high Broad host access to all HTTP sites; enables content injection.
  • https://*/* high Broad host access to all HTTPS sites; enables content injection.

Pillar Scores

Permissions6.00
Reputation6.50
Network2.00
Webstore1.00
Maintenance6.00
Privacy9.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:55
Listing SHA 9207fee5ba1e…
Force block — not fired
Score recovered no
Elapsed