Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

The Anonymous Board

mfobnlidicoeaihigfpepgmfgekgalcn
Risk Score
3.46
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 37
Rating
Last updated 2025-12-04 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer epaladino72@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope to this extension, admits data collection and 3rd-party sharing.
  • Developer uses free webmail (gmail) with no listed developer name or business website.
  • No CSP declared (MV3 default mitigates but adds no explicit restriction).
  • Very low install base (37) provides minimal community vetting signal.
  • Maintenance window at 6 months — borderline stale, approaching 6-12 month penalty tier.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • free_webmail_dev_no_name store Developer email epaladino72@gmail.com, developer_name empty, no business website → reputation +1.5.
  • no_csp manifest content_security_policy is null; MV3 strict default applies, no v2 network penalty triggered.
  • no_bad_hosts_no_affiliates crx threat_intel shows empty bad_host_hits, affiliate_hits, monetization_hits — no network threat signals.
  • code_clean crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — no code quality risk.
  • narrow_host_scope manifest content_scripts limited to *://*.chess.com/* only; no broad host access.
  • maintenance_borderline store months_since_update=6; falls in 3-6 month band → +1.5 maintenance score.
  • cve_none crx cve_findings_raw is empty; CVE pillar = 0.0.

Permissions Breakdown

  • activeTab low Grants access only to current tab on user gesture; scoped and temporary.
  • storage low Local extension storage only; no cross-origin data risk.
  • windows low Can read window state; low risk without broad host access.
  • system.display low Read-only display configuration; limited privacy impact.

Pillar Scores

Permissions1.30
Reputation6.50
Network0.00
Webstore0.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA d088ca683f14…
Force block — not fired
Score recovered no
Elapsed 20.5s