Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

YouTube Ad Accelerator & Easy Speed Drag

lmcggcabhocpfkbddekmconplfjmmgmn
Risk Score
4.56
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 10,000
Rating 4.5
Last updated 2025-06-09 (12 months ago)
Manifest version MV3
CSP present ✅ yes
Developer davidschiller138@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy—scope_extension=false, data_collection=true, third_party_sharing=true: effectively admits broad data use with no extension-specific scoping.
  • Brand impersonation: YouTube brand used in name/description by unverified gmail developer with no business identity.
  • Install URL hijack flag set (install_url_hijack=true) and uninstall URL redirects to third-party dev domain.
  • Developer is anonymous (no name, free-webmail email, no verified publisher despite badge) — accountability gap.
  • Extension is 12 months since last update; maintenance borderline stale for a YouTube-targeted content script.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; YouTube brand in title, developer is gmail user with no confirmed ownership.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true per classifier.
  • install_url_hijack crx install_url_hijack=true; install_url_target=null — exact target unknown but flag raised.
  • uninstall_url_hijack crx Uninstall redirects to https://davidschiller.net/uninstalled-easy-speed-drag-for-youtube.html (third-party domain).
  • anonymous_developer store developer_name empty; email is free-webmail davidschiller138@gmail.com; no verified publisher badge per data.
  • verified_publisher store verified_publisher=true AND is_featured_by_google=true; partially mitigates reputation but caps limited by policy issues.
  • scripting_plus_host manifest scripting + *://www.youtube.com/* allows dynamic JS injection into YouTube pages.
  • maintenance store Last updated June 2025; months_since_update=12; in 6-12mo band → +3.5.

Permissions Breakdown

  • activeTab low Grants access to current tab only on user action; scoped risk.
  • storage low Local data persistence; no exfil risk alone.
  • scripting medium Allows dynamic script injection; medium risk when paired with host permissions.
  • *://www.youtube.com/* medium Host permission scoped to YouTube only; moderate reach on a major platform.

Pillar Scores

Permissions2.30
Reputation7.00
Network0.00
Webstore5.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA f81b39417442…
Force block — not fired
Score recovered no
Elapsed 21.7s