Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

YouTube Music Beautifier

mfgecbliilfimjghneojngcbificbdpa
Risk Score
3.09
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 3,000
Rating 4.2
Last updated 2026-04-10 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer customersupport@langstudy.tech
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension is named after YouTube (Google property) but developer is unverified third party.
  • DOM-XSS sink in displayer.js: innerHTML assigned from variable without sanitisation.
  • CSP connect-src allows multiple unknown nwvbug.com subdomains (ws.nwvbug.com, ytm.nwvbug.com, etc.).
  • Privacy policy does not disclose data retention; third-party sharing silence noted.
  • Developer name blank; identity accountability gap despite verified-publisher status.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'youtube'; developer is not confirmed owner.
  • dom_xss_sink crx displayer.js: innerHTML assigned from 'totalhtml' variable — uncontrolled DOM sink.
  • unknown_external_hosts crx CSP/js_external_hosts include ws.nwvbug.com, wsbeta.nwvbug.com, ytm.nwvbug.com, ytmbeta.nwvbug.com.
  • verified_publisher store verified_publisher=true; partially mitigates reputation risk but does not explain nwvbug.com endpoints.
  • privacy_policy_partial api Policy fetched, scope_extension=true, data_collection=false, but retention=false and third_party_silence=true.
  • developer_name_missing store developer_name is empty string; reduces identity accountability.
  • content_script_scoped manifest content_scripts limited to https://music.youtube.com/* — matches stated YouTube Music function.
  • no_cve_findings crx cve_findings_raw is empty; no known-vulnerable bundled libraries detected.

Permissions Breakdown

  • storage low Standard key-value store for user preferences; no cross-origin risk.
  • offscreen low Allows off-screen DOM; needed for audio/media processing but no broad host access.
  • content_scripts: https://music.youtube.com/* medium Runs JS on YouTube Music; scoped to single domain, matches stated feature set.

Pillar Scores

Permissions0.60
Reputation6.00
Network3.50
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA d54452685358…
Force block — not fired
Score recovered no
Elapsed 20.9s