Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Momentum

laookkfknpbbblfpciffpaejjkokdgca
Risk Score
4.00
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 2,000,000
Rating 4.5
Last updated 2026-07-28 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@momentumdash.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false and third_party_sharing=true; data sharing admitted without extension-specific scoping.
  • NewTab override replaces every new tab for 2M users; very high reach.
  • function_constructor (new Function) in lib JS is a dynamic code execution pattern.
  • innerHTML from variable (DOM-XSS sink) present; CSP mitigates but not eliminates risk.
  • No developer name listed; policy lacks extension-specific data collection disclosure.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set to index.html — replaces new tab for all 2M users.
  • privacy_policy_scope_mismatch crx Policy fetched; scope_extension=false, data_collection=false but third_party_sharing=true. v3.5(D) → +10.0 privacy.
  • function_constructor crx new Function() in lib-DRkOfJU3.js — dynamic code execution path.
  • dom_sink_innerhtml crx innerHTML from variable in index-D_OoZHl5.js; CSP present reduces severity.
  • no_developer_name store developer_name is empty string; reputation starts elevated without verified identity.
  • featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied.
  • no_bad_hosts_no_affiliate crx threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — clean threat intel.
  • cve_findings_empty crx cve_findings_raw=[]; no known vulnerable libraries detected.

Permissions Breakdown

  • offscreen low Creates offscreen documents; limited capability on its own.
  • unlimitedStorage low Allows large local storage; no direct data-exfil risk alone.
  • idle low Detects user idle state; minimal privacy impact.
  • chrome_url_overrides.newtab medium Replaces every new tab; high reach, typical for NewTab category but still elevated.

Pillar Scores

Permissions3.30
Reputation4.50
Network2.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure0.00

Scoring History

fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.34 Low review 2026-08-03
fsssiedxa"sssiedx 3.14 Low review 2026-08-03
sssieddrubricxsx 3.21 Low review 2026-08-03
v3.6 4.00 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA 177d39edffcf…
Force block — not fired
Score recovered no
Elapsed 24.0s