Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

My Notes

lkeeogfaiembcblonahillacpaabmiop
Risk Score
4.82
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 20,000
Rating 4.7
Last updated 2024-04-25 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer bucka.pavel@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is a generic auto-generated template admitting data collection and 3rd-party sharing without scoping to this extension.
  • Extension is 26 months stale — abandoned or unmaintained, acquisition risk elevated.
  • Developer uses free Gmail address with no verified business identity.
  • Host permission to drive.google.com could access user files if extension is compromised or sold.
  • No CSP declared (MV3 default applies, but adds no defense-in-depth signals).

Evidence

  • privacy_policy_generic_admits_collection api Policy from privacypolicygenerator.info: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • maintenance_stale_26mo store Last updated April 2024; 26 months since update → +8.5 maintenance pillar.
  • developer_free_webmail store Dev email bucka.pavel@gmail.com; no business domain; domain_age_ct not queried (free webmail).
  • featured_by_google store is_featured_by_google=true; provides -2.0 reputation discount but not verified publisher.
  • drive_host_permission manifest host_permissions includes https://drive.google.com/ — can read/write user Google Drive data.
  • no_cve_no_bad_hosts api cve_findings_raw=[], bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — clean threat intel.
  • code_findings_empty crx 0 JS files scanned, obfuscation_score=0.0, code_findings_raw=[] — no malicious code signals.
  • operator_cluster_singleton api sibling_count=0; no operator cluster pattern detected.

Permissions Breakdown

  • storage low Standard local data persistence; expected for note-taking app.
  • unlimitedStorage low Allows larger storage quota; low risk for a notes app.
  • contextMenus low Adds right-click menu items; no data exfil capability alone.
  • notifications low Desktop notifications; could be abused for spam but low standalone risk.
  • https://drive.google.com/ medium Host access to Google Drive; could read/write user drive files.

Pillar Scores

Permissions1.30
Reputation6.50
Network2.00
Webstore1.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA 9ae8b06f1982…
Force block — not fired
Score recovered no
Elapsed 22.3s