Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Chrome Notes

lnfempckkegmaeleniojhjplemmebgfi
Risk Score
4.03
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 100,000
Rating 4.4
Last updated 2025-10-20 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@rgbstudios.org
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy hosted on generic freeprivacypolicy.com and could not be fetched — scored as no policy.
  • brand_mention flags 'google' as impersonation (extension named 'Chrome Notes', unverified owner).
  • install_url_hijack flag set — onInstalled may open a third-party URL.
  • DOM-XSS sink (innerHTML from user-controlled variable) with no CSP in MV3 extension.
  • No developer name listed; identity accountability reduced despite verified publisher badge.

Evidence

  • privacy_policy_fetch_failed api Privacy policy on freeprivacypolicy.com returned HTTPError; treated as unfetched → +10.0 privacy pillar.
  • brand_impersonation store brand_mention.is_impersonation=true for 'google'; verified_publisher present → +1.0 reputation.
  • install_url_hijack crx install_url_hijack=true; target null. Penalised as install-URL hijack (+2.0 webstore).
  • dom_xss_sink_no_csp crx dom_sink_innerhtml_userctrl in scripts.js; csp_present=false → elevated to +2.0 code quality.
  • no_developer_name store developer_name is empty string; +1.0 reputation for missing 'Offered by' identity.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied to reputation pillar.
  • installs_100k store 100,000 installs → +1.0 webstore reach signal.
  • no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.

Permissions Breakdown

  • clipboardWrite medium Can write arbitrary content to clipboard; expected for a notes app.
  • clipboardRead medium Can silently read clipboard contents; moderate privacy risk.
  • downloads medium Can trigger file downloads; reasonable for note export.
  • contextMenus low Adds right-click menu entries; low risk, common utility pattern.

Pillar Scores

Permissions2.30
Reputation3.50
Network0.00
Webstore4.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA 4fae2b880cbd…
Force block — not fired
Score recovered no
Elapsed 22.4s