Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Anonymous HTTP Proxy

meifgfdnekgimiclillpbogbblbfbaeg
Risk Score
5.04
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 197
Rating 3.0
Last updated 2025-01-30 (17 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@getbehind.me
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy permission allows full rerouting of all browser traffic through developer-controlled infrastructure
  • Privacy policy fetched but admits data collection and third-party sharing without scoping to this extension — highest privacy risk tier
  • No developer name listed; low install count (197) with high-impact permission is a tail-attack-surface flag
  • Extension stale at 17 months; verified-publisher cap applies due to months_since_update > 18 proximity and monetization-adjacent concerns
  • External JS hosts include github.com and www.apache.org — unexpected for a proxy tool; warrants code review

Evidence

  • proxy_permission manifest proxy declared — can intercept and reroute all browser HTTP/HTTPS traffic to any server.
  • privacy_policy_scope_fail api Policy fetched (94k chars), scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy.
  • no_developer_name store developer_name is empty string; email-only identity support@getbehind.me.
  • install_perm_anomaly api small_install_high_perm=true, tail_attack_surface=true; 197 installs with proxy permission.
  • verified_publisher store verified_publisher=true; discount applied but capped due to months_since_update=17 approaching 18mo threshold.
  • external_js_hosts crx js_external_hosts includes github.com and www.apache.org — unexpected for a proxy extension.
  • low_rating store Rating 3.0; no review red flags detected (match_count=0).
  • maintenance_stale store Last updated January 30 2025; months_since_update=17 → +3.5 maintenance score.

Permissions Breakdown

  • proxy high Full proxy control — can reroute all browser traffic through attacker-controlled servers.
  • storage low Stores extension config locally; low standalone risk.
  • alarms low Scheduled task triggers; low risk in isolation.

Pillar Scores

Permissions5.50
Reputation5.00
Network2.00
Webstore4.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA 794651326ca6…
Force block — not fired
Score recovered no
Elapsed 18.9s