Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Udemy Subtitle Translator - Yakuu

mfjgefhkaljdlpmnnfcaebgmchfhakcf
Risk Score
5.10
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 10,000
Rating 4.1
Last updated 2023-02-21 (41 months ago)
Manifest version MV3
CSP present ❌ no
Developer twampd@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned extension: 41 months since last update — no security patches since Feb 2023.
  • Privacy policy is Google's own policy (myaccount.google.com), not scoped to this extension at all.
  • Free-webmail developer (twampd@gmail.com) with no verified identity or business domain.
  • No content_security_policy declared (MV3, so no network amplifier, but CSP gap still present).
  • Triple-stale fingerprint: >24mo stale + MV3 no CSP + free-webmail dev with no accountability.

Evidence

  • maintenance_stale store Last updated Feb 21 2023; 41 months elapsed — maintenance pillar max 10.0 plus zombie booster (+1.0 >36mo & >10K installs, capped).
  • privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • developer_free_webmail store Developer email twampd@gmail.com; no business website; not verified publisher.
  • is_featured_by_google store Extension carries 'Featured' badge — applied -2.0 reputation discount.
  • no_csp manifest content_security_policy is null; MV3 so no +2.0 network penalty, but CSP gap is present.
  • host_permissions_scope manifest Hosts: udemy.com, youtube.com, translate.googleapis.com — scoped; justified for translation tool.
  • no_code_findings crx 0 code findings, obfuscation_score=0.0; 6 JS files scanned — code quality pillar 0.0.
  • wayback_ownership api Wayback check completed; no ownership change detected (fetch_error:ReadTimeout, no snapshot).

Permissions Breakdown

  • scripting medium Can inject JS into matched pages (udemy, youtube); scoped to declared hosts.
  • storage low Stores local settings; no cross-site risk.
  • tabs medium Can read tab URLs; needed for subtitle injection but moderate capability.
  • declarativeContent low Controls when extension icon is active; minimal risk.
  • https://*.udemy.com/* medium Full access to Udemy pages including auth/session data.
  • https://*.youtube.com/* medium Full access to YouTube pages; broader than stated translation focus.
  • https://translate.googleapis.com/* low Scoped to Google Translate API; matches stated translation function.

Pillar Scores

Permissions2.50
Reputation5.50
Network0.00
Webstore1.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-16 13:28
Listing SHA 9c7626d36d94…
Force block — not fired
Score recovered no
Elapsed