Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bookmarks Quick Search

lniofgaicnjjdfinpnkhmlpmnhacnkca
Risk Score
5.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 20,000
Rating 4.6
Last updated 2023-06-05 (36 months ago)
Manifest version MV3
CSP present ❌ no
Developer bookmarks.quick.search@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • No privacy policy: links to generic Google account policy that does not scope to this extension, scores max.
  • Extension not updated in 36 months — at maintenance ceiling; abandoned risk.
  • code_findings include function_constructor and script_src_dynamic — webpack code-splitting patterns but no CSP to contain abuse.
  • Developer uses free Gmail address with no verified business identity.
  • innerHTML sink with no CSP present raises DOM-XSS exposure.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
  • maintenance_stale store Last updated June 2023; months_since_update=36 → +8.5 Maintenance ceiling.
  • free_webmail_dev store Developer email bookmarks.quick.search@gmail.com; no business domain → Reputation +1.5.
  • is_featured_by_google store Featured badge present → Reputation -2.0.
  • code_quality_dynamic_script crx script_src_dynamic and function_constructor signals in main JS bundle; no CSP to restrict.
  • no_csp manifest content_security_policy is null (MV3 default strict applies but no explicit custom CSP). dom_sink_innerhtml_userctrl scores +2.0.
  • no_bad_hosts crx threat_intel bad_host_hits and affiliate_hits empty; single external JS host reactjs.org (benign CDN reference).
  • cve_none crx cve_findings_raw is empty; CVE pillar = 0.0.

Permissions Breakdown

  • bookmarks medium Read/write access to all user bookmarks; core to stated function.
  • declarativeContent low Allows showing page-action based on URL; no data exfil risk.
  • favicon low Access to favicon URLs; minimal risk.
  • activeTab low Temporary access to active tab on user action only.

Pillar Scores

Permissions1.60
Reputation6.50
Network2.00
Webstore1.00
Maintenance8.50
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA b5dbfb851d0b…
Force block — not fired
Score recovered no
Elapsed 25.8s