Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Disable Cookies

lkmjmficaoifggpfapbffkggecbleang
Risk Score
4.51
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 20,000
Rating 3.9
Last updated 2025-01-31 (17 months ago)
Manifest version MV3
CSP present ❌ no
Developer singleclickapps@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched and admits data collection + third-party sharing but is NOT scoped to this extension — worst-case privacy posture.
  • Free-webmail developer (gmail.com) with no 'Offered by' name; accountability gap.
  • browsingData + contentSettings combo allows silent clearing of all cookies/browsing data across all sites.
  • Uninstall URL hijack sends user to developer domain on removal — minor monetization/tracking signal.
  • Featured badge and verified publisher discount capped to -1.0 due to months_since_update=17 exceeding 18mo threshold imminently; policy still unscoped.

Evidence

  • privacy_policy_scope_mismatch api Policy fetched (55k chars), scope_extension=false, data_collection=true, third_party_sharing=true → D rule fires: +10.0 privacy.
  • free_webmail_dev_no_name store developer_email=singleclickapps@gmail.com, developer_name empty; reputation +1.5 free-webmail, +1.0 no Offered-by name.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; reputation discounts applied but capped by months=17 approaching 18mo threshold.
  • uninstall_url_hijack crx onUninstall → singleclickapps.com/disable-cookies/removed-chrome.html; webstore +3.0 but category-context reduces concern.
  • install_url_opens_settings crx install_url_hijack=true targeting chrome://settings/content/siteData — benign internal page, not 3rd-party.
  • no_csp manifest content_security_policy=null on MV3; MV3 strict default applies, no +2.0 MV2 penalty triggered.
  • high_perm_browsingData_contentSettings manifest Two HIGH permissions; justified-broad discount (-1.5) applied as PrivacyTool category matches stated function.
  • no_code_findings_no_cves crx code_findings_raw=[], cve_findings_raw=[], obfuscation_score=0.0; code quality and CVE pillars score 0.

Permissions Breakdown

  • contentSettings high Can control browser content settings (cookies, JS, plugins) per-site — core function but high capability.
  • browsingData high Can delete cookies, cache, history, and other browsing data across all sites.
  • tabs medium Access to tab URLs and navigation events; needed to identify current site.
  • contextMenus low Adds right-click menu entries; low risk on its own.
  • storage low Local extension settings persistence; low risk.

Pillar Scores

Permissions5.50
Reputation4.50
Network0.00
Webstore4.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA c2f1d28cc781…
Force block — not fired
Score recovered no
Elapsed 25.9s