Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Open in Foxit™ Reader

lhplfipknbnglagbgbfogdaihdcekfga
Risk Score
5.84
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category ReaderMode
Installs 40,000
Rating 2.8
Last updated 2025-12-22 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer lunu.bounir@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • nativeMessaging with unrecognized publisher: direct bridge to local OS from every page the user visits.
  • content_scripts on <all_urls> gives the extension DOM access to every site despite narrow stated function.
  • Privacy policy is Google's own policy (not scoped to this extension); admits data collection and 3rd-party sharing.
  • Developer uses free Gmail address with no verifiable business identity; install/uninstall URL hijack detected.
  • Rating 2.8 is low; extension talks to github.com/api.github.com for unknown purposes with no CSP.

Evidence

  • nativeMessaging_unrecognized_publisher crx has_native_messaging=true, publisher_recognized=false; +3.0 on permissions per rule 15.
  • content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] injected on every page despite PDF-opener stated function.
  • privacy_policy_generic_google store Policy URL is myaccount.google.com; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • install_uninstall_url_hijack crx install_url_hijack=true (target: /data/helper/index.html); uninstall_url_hijack=true.
  • free_webmail_developer store Developer email lunu.bounir@gmail.com; no verified business website; reputation floor 7.5.
  • js_external_hosts_github crx Extension contacts api.github.com and github.com; purpose undisclosed in manifest description.
  • low_rating store Rating 2.8; no confirmed review red-flags in structured data but below-average user satisfaction.
  • no_csp manifest content_security_policy=null on MV3; no additional CSP hardening present.

Permissions Breakdown

  • storage low Stores local extension settings; low impact.
  • contextMenus low Adds right-click menu items; limited surface.
  • notifications low Desktop notifications; low risk on its own.
  • nativeMessaging high Calls local Foxit Reader companion app; publisher_recognized=false raises risk significantly.
  • downloads medium Can initiate or intercept downloads; moderate risk.
  • activeTab low Access to current tab on user action only; low impact.
  • content_scripts:<all_urls> high Content script injected into every page; broad reach amplifies any code risk.

Pillar Scores

Permissions7.50
Reputation7.50
Network0.00
Webstore6.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA 59c4547df026…
Force block — not fired
Score recovered no
Elapsed 22.0s