Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Export My NFT Listings

lpmogjockhdkcepliphdfbhpcdacbhki
Risk Score
6.07
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Other
Installs 2,000
Rating 4.0
Last updated 2021-12-28 (54 months ago)
Manifest version MV3
CSP present ❌ no
Developer jesse@itjesse.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned: last updated Dec 2021 (54 months ago), unpatched against any future platform changes or security issues.
  • Privacy policy points to generic Google policy (scope_extension=false, admits data collection and 3rd-party sharing) — effectively no extension-scoped policy.
  • webRequest permission can observe all network traffic on NFT marketplace hosts, including wallet and authentication data.
  • Developer domain itjesse.com does not resolve — no accountability or support channel.
  • function_constructor pattern in 4 bundled JS files without CSP; no content_security_policy declared.

Evidence

  • abandoned_extension store Last updated December 2021; 54 months since update — no maintenance for 4.5 years.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_domain_dead api itjesse.com does not resolve per threat_intel; no reachable developer contact or policy page.
  • no_csp manifest content_security_policy is null (MV3); no additional script-src hardening declared.
  • function_constructor crx new Function() found in popup.js, nftrade.js, scv.js, opensea.js — dynamic code construction pattern.
  • webRequest_high_perm manifest webRequest declared with access to NFT marketplace hosts including wallet-bearing OpenSea sessions.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; low-install extension with high-tier permissions.
  • featured_by_google store is_featured_by_google=true; partial trust signal but does not offset abandonment or privacy gaps.

Permissions Breakdown

  • clipboardWrite medium Can write to clipboard; used for CSV export but permits silent data injection.
  • tabs medium Access to tab URLs and navigation; medium risk in combination with scripting.
  • webRequest high Can observe all network requests to permitted hosts; allows traffic interception.
  • background low Keeps service worker alive; low risk alone.
  • storage low Local extension storage; standard, low risk.
  • scripting medium Can inject scripts into permitted host origins; medium risk scoped to declared hosts.
  • host:https://nftrade.com/ medium Scoped to NFT marketplace; consistent with stated function.
  • host:https://api.nftrade.com/ medium Scoped to NFTrade API; consistent with stated function.
  • host:https://scv.finance/ medium Scoped to SCV Finance NFT portfolio; consistent with stated function.
  • host:https://opensea.io/ medium Scoped to OpenSea; consistent with stated function.
  • host:https://api.opensea.io/ medium Scoped to OpenSea API; consistent with stated function.

Pillar Scores

Permissions4.50
Reputation5.50
Network3.50
Webstore3.00
Maintenance10.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA 140c230f8611…
Force block — not fired
Score recovered no
Elapsed 27.8s