Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Markdown Reader

medapdbncneneejhbgcjceippjlfkmkg
Risk Score
1.88
Risk Level: Low
Recommendation: ✅ ALLOW
Category ReaderMode
Installs 100,000
Rating 4.7
Last updated 2026-09-05
Manifest version MV3
CSP present ✅ yes
Developer benjavan@163.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Developer email on 163.com (free Chinese webmail) with no dev name listed; identity unverifiable.
  • Content scripts match broad wildcard file-extension patterns across all HTTP/file origins.
  • Privacy policy discloses third-party data sharing; actual scope to this extension confirmed.
  • Uninstall URL hijack flag set (target null); minor concern but worth noting.
  • No developer name provided; reduced accountability.

Evidence

  • verified_publisher + featured store Extension carries both verified_publisher and is_featured_by_google badges; strong trust signal.
  • developer_email_domain store Developer email benjavan@163.com on free Chinese webmail; no business domain; looks_throwaway=true.
  • content_scripts_scope manifest Content scripts scoped to markdown/txt/md file extensions on *://*/ and file://; not all_urls.
  • privacy_policy_classification api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
  • no_bad_hosts_no_cves crx No bad host hits, no CVEs, no affiliate/monetization hits, obfuscation_score=0, code_findings empty.
  • uninstall_url_hijack crx uninstall_url_hijack=true but target is null; may be benign feedback page.
  • js_external_hosts crx CSP script-src is 'self' only; external hosts developer.mozilla.org and vuejs.org in HTML links only.
  • maintenance store Last updated June 2026; months_since_update=0; actively maintained.

Permissions Breakdown

  • storage low Stores user preferences locally; no exfil risk.
  • tabs medium Can read tab URLs/titles; moderate privacy surface.
  • content_scripts (*://*/*.md etc.) medium Injects into markdown/text file URLs across all hosts; scoped to file-type pattern, not all_urls.

Pillar Scores

Permissions2.30
Reputation3.50
Network0.00
Webstore2.50
Maintenance0.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiednecaa3818dp727562726963xsx 2.07 Low allow 2026-09-07
<fsssiedxa'sssiedx 1.88 Low allow 2026-08-13
<fsssiedxa 1.75 Low allow 2026-08-13
<fsssiedxa$"sssiedx 2.44 Low allow 2026-08-13
xx pfsssiedxasssiedx 1.61 Low allow 2026-08-08
"fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 1.93 Low allow 2026-08-08
%22fsssiedxa$"sssiedx 2.09 Low allow 2026-08-08
%27fsssiedxa$"sssiedx 1.70 Low allow 2026-08-08
&#x27;fsssiedxa$'sssiedx 2.25 Low allow 2026-08-08
1.99 Low allow 2026-08-08
fsssiedxa<sssiedx 1.74 Low allow 2026-08-08
fsssiedxa sssiedx 1.54 Low allow 2026-07-28
fsssiedxa"sssiedx 1.37 Low allow 2026-07-28
fsssiedxa&#x27;sssiedx 1.45 Low allow 2026-07-28
fsssiedxa$'sssiedx 1.61 Low allow 2026-07-28
sssieddrubricxsx 1.67 Low allow 2026-07-28
v3.6 1.88 Low allow 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA 9bb1ce9a9f9c…
Force block — not fired
Score recovered no
Elapsed 19.7s