Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

StayFocusd – Website Blocker & Focus Timer & Shorts Blocker

laankejkbhbdhmipfmgcngdelahlfoji
Risk Score
4.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 700,000
Rating 4.4
Last updated 2026-06-09
Manifest version MV3
CSP present ❌ no
Developer support@stayfocusd.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy hosted on SensorTower (third-party analytics company), not scoped to this extension; admits data collection and third-party sharing.
  • Broad content scripts injected on all URLs (*://*/*) gives extension reach into every page the user visits.
  • Uninstall URL hijack flag is set — extension registers an uninstall URL pointing to unknown third-party destination.
  • DOM-XSS sink (innerHTML) found in bundled JS without a CSP, increasing exploitability if attacker controls tooltip variable.
  • No developer name listed; privacy policy domain (sensortower.com) does not match developer domain (stayfocusd.com), indicating policy may not be authoritative.

Evidence

  • privacy_policy_not_scoped api Policy on sensortower.com: scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy (D rule).
  • uninstall_url_hijack crx uninstall_url_hijack=true; target unknown. Webstore +3.0 applied.
  • broad_content_scripts manifest content_scripts_matches includes *://*/* and http://*/* — injection on all URLs.
  • dom_xss_sink_no_csp crx innerHTML userctrl sink in chunks/index-D-Dq_vpe.js; csp_present=false raises score to +2.0.
  • description_permission_mismatch store Promises ad-blocking but lacks declarativeNetRequest/webRequest. +2.0 Webstore.
  • no_developer_name store developer_name is empty string; +1.0 Reputation.
  • featured_by_google store is_featured_by_google=true; -2.0 Reputation discount applied.
  • js_external_hosts crx 12 external JS hosts including purchases.stayfreeapps.com, accounts.google.com, googleapis.com — >3 distinct domains.

Permissions Breakdown

  • storage low Stores user blocking config locally; standard for productivity tools.
  • tabs medium Can read tab URLs and titles; needed for blocking but grants broad URL visibility.
  • alarms low Schedules focus timers; no sensitive data access.
  • webNavigation medium Observes navigation events across all sites; needed for URL blocking enforcement.
  • notifications low Displays focus alerts; no data exfil risk.
  • identity medium OAuth token access; could expose Google identity. Scope unknown.
  • content_scripts *://*/* high Broad content script injection on all URLs — matches stated blocking function but high reach.

Pillar Scores

Permissions3.80
Reputation5.50
Network1.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

v3.6 4.28 Medium review 2026-06-16
v3.4-rev 4.02 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA 04c6b733a359…
Force block — not fired
Score recovered no
Elapsed 25.5s