Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Page Locker

ldmnhdllijbchflpbmnlgndfnlgmkgif
Risk Score
4.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 95
Rating 5.0
Last updated 2026-07-19 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer viktornadiezhdin@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (gmail) with no developer name; verified-publisher discount applies but identity accountability low.
  • scripting + <all_urls> + content_scripts on all URLs: full arbitrary code injection capability on every site.
  • Privacy policy hosted on cloudapi.stream CDN (same domain as JS hosts); third_party_silence flag raised.
  • 12 external JS hosts including raw.githubusercontent.com and bootstrap.gallery — broad remote dependency surface.
  • small_install_high_perm anomaly: only 95 installs but full broad-host + scripting permissions.

Evidence

  • free_webmail_dev_no_name store developer_email=viktornadiezhdin@gmail.com; developer_name empty; no verified business identity.
  • verified_publisher store verified_publisher=true; reduces reputation risk but capped due to free-webmail identity.
  • scripting_plus_all_urls manifest permissions=[scripting] + host_permissions=[<all_urls>] + content_scripts on <all_urls>; full code injection reach.
  • external_js_hosts_12 crx 12 external JS hosts including raw.githubusercontent.com, bootstrap.gallery, cloudapi.stream; broad remote dep surface.
  • privacy_policy_cdn_hosted store Privacy policy at cdn.cloudapi.stream; third_party_silence=true; policy fetched, scoped, but silence on 3rd-party sharing.
  • dom_xss_sink crx innerHTML assignment from variable in daterange.js; DOM-XSS risk present without aggressive CSP on sandbox.
  • sandbox_csp_unsafe_eval manifest Sandbox CSP allows unsafe-inline and unsafe-eval; mitigates extension_pages CSP hardening.
  • install_perm_anomaly api 95 installs with high-tier permissions (scripting+<all_urls>); tail-attack-surface flag raised.

Permissions Breakdown

  • storage low Local data persistence only.
  • tabs medium Can read tab URLs and metadata across all tabs.
  • webNavigation medium Monitors navigation events across all sites.
  • sidePanel low UI surface only, low standalone risk.
  • scripting high Can inject arbitrary scripts into pages; paired with <all_urls>.
  • declarativeNetRequest medium Can block/redirect network requests declaratively.
  • activeTab low Scoped to user-activated tab only.
  • <all_urls> (host) high Grants access to every site; amplifies scripting and webNavigation.
  • <all_urls> (content_scripts) high Content scripts injected on every page the user visits.

Pillar Scores

Permissions7.50
Reputation6.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:11
Listing SHA 8f89569b2e12…
Force block — not fired
Score recovered no
Elapsed