Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

StackOverflow Code Snippet Copier

mcgnogkmgagddkecfcfakidaamdchkja
Risk Score
5.78
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 103
Rating 4.5
Last updated 2023-05-27 (37 months ago)
Manifest version MV3
CSP present ❌ no
Developer vaibhav.jain197@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • Extension abandoned: 37 months since last update (>36mo maintenance score 10.0).
  • Brand impersonation: 'StackOverflow' in name, developer is unverified gmail user with no confirmed ownership.
  • Free-webmail developer (gmail) with no business website raises identity accountability concerns.
  • No CSP declared (MV3 has strict default, but adds +2.0 Network for MV2 check — MV3 so +2.0 not applied; still no policy transparency).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false; developer is gmail user 'vaibhav.jain197@gmail.com'.
  • privacy_policy_generic store Policy is Google account policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 D).
  • maintenance_abandoned store months_since_update=37 (>36mo) → Maintenance pillar 10.0.
  • free_webmail_developer store Developer email is gmail.com; no business domain; developer name only 'VJ'.
  • is_featured_by_google store is_featured_by_google=true; provides partial reputation mitigation but stale update reduces discount.
  • no_cve_no_bad_hosts crx cve_findings_raw empty, bad_host_hits empty, affiliate_hits empty, monetization_hits empty.
  • code_clean crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty, 3 JS files scanned.
  • narrow_host_scope manifest content_scripts scoped only to https://stackoverflow.com/*; no broad host permissions.

Permissions Breakdown

  • clipboardWrite medium Allows writing to clipboard; expected for a copy-button tool, low abuse potential alone.
  • content_scripts: https://stackoverflow.com/* low Narrowly scoped to stackoverflow.com only; matches stated function.

Pillar Scores

Permissions1.00
Reputation7.50
Network2.00
Webstore3.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA e4bf7604133f…
Force block — not fired
Score recovered no
Elapsed 20.7s