Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Zoom for Google Chrome

lajondecmobodlejlcjllhojikagldgd
Risk Score
3.88
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 300,000
Rating 4.2
Last updated 2025-12-29 (6 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@stefanvd.net
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses 'Zoom' and 'Google' brand names but developer is unverified third party (stefanvd.net).
  • <all_urls> host permission with content_scripts injected on every site visited.
  • Developer name blank; verified_publisher badge does not confer brand legitimacy.
  • 12 diverse external JS hosts in CSP including social/ad-adjacent domains (connect.qq.com, service.weibo.com).
  • Privacy policy discloses third-party data sharing with extension scope — data collection acknowledged.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands 'zoom' and 'google' used; confirmed_owner=false; dev domain stefanvd.net.
  • host_permissions_all_urls manifest host_permissions=[<all_urls>] AND content_scripts_matches=[<all_urls>]; broad injection surface.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; mitigates some reputation risk but not impersonation.
  • js_external_hosts crx 12 external hosts in CSP incl. connect.qq.com, service.weibo.com, x.com — diverse geo/origin spread.
  • privacy_policy_third_party api privacy_policy_classification: scope=true, data_collection=true, third_party_sharing=true, retention=true.
  • no_code_findings crx code_findings_raw=[], obfuscation_score=0.0; no malicious JS patterns detected.
  • no_cve_findings crx cve_findings_raw=[]; no known vulnerable libraries bundled.
  • sibling_dev_email api operator_cluster.sibling_counts_by_dim.dev_email=3; same email linked to 3 other extensions.

Permissions Breakdown

  • tabs medium Access tab URLs and metadata; medium risk on its own.
  • contextMenus low Adds right-click menu items; minimal data access.
  • storage low Local extension data storage only.
  • scripting medium Can inject JS into pages; elevated with <all_urls>.
  • webNavigation medium Monitors navigation events across all tabs.
  • system.display low Read display configuration; limited scope.
  • unlimitedStorage low Allows large local storage; no data exfil risk alone.
  • <all_urls> (host) high Content scripts injected on all sites; broadest surface.

Pillar Scores

Permissions6.00
Reputation6.50
Network2.50
Webstore3.50
Maintenance1.50
Privacy1.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA c39f3e8b907a…
Force block — not fired
Score recovered no
Elapsed 21.0s