Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Google Dictionary (by Google)

mgijmajocgfcbeboacabfgobmjgjcoja
Risk Score
3.24
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 3,000,000
Rating 4.4
Last updated 2026-02-09 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer dictionary-extension-dev@google.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic corporate policy; does NOT scope data collection to this extension, admits 3rd-party sharing (+10.0 privacy).
  • Content script on <all_urls> gives extension read access to every page the user visits.
  • No CSP declared (MV3 default applies, but no explicit scoping of extension pages).
  • Google Analytics telemetry endpoint contacted; policy doesn't explain what is sent.
  • 3M installs amplify any future compromise or policy-drift impact.

Evidence

  • content_scripts_all_urls manifest content_scripts_matches=["<all_urls>"] — script runs on every page visited.
  • privacy_policy_generic store policies.google.com/privacy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
  • featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount (featured badge).
  • recognized_org store developer_email @google.com + confirmed_owner=true; -2.0 reputation but CAPABILITY GATE: content_scripts <all_urls> is HIGH capability, caps discount.
  • monetization_hit_telemetry api www.google-analytics.com in monetization_hits; telemetry-tier only → +1.0 webstore.
  • no_cve_findings crx cve_findings_raw=[] — no vulnerable bundled libraries detected.
  • no_code_findings crx code_findings_raw=[], obfuscation_score=0.0 — clean code scan.
  • maintenance_recent store months_since_update=4 — within 3-6 month band → +1.5 maintenance.

Permissions Breakdown

  • storage low Stores user preferences/history locally; no cross-site data risk.
  • content_scripts:<all_urls> high Content script injected on all URLs; can read page content on every site visited.

Pillar Scores

Permissions3.50
Reputation2.00
Network2.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedn3ead60b6dp727562726963xsx 3.28 Low review 2026-09-10
fsssiedxn4a7f8c29za xx pn4a7f8c29zsssiedx 3.45 Low allow 2026-09-09
sssiedn6774c0addp727562726963xsx 3.18 Low review 2026-09-09
sssiedn34b3102adp727562726963xsx 3.27 Low review 2026-09-07
v3.69173"();}]9874 3.14 Low review 2026-08-05
dfb__${98991*97996}__::.x 2.93 Low review 2026-08-05
dfb{{98991*97996}}xca 2.98 Low allow 2026-08-05
'"()&%<zzz><ScRiPt >t4aX(9154)</ScRiPt> 2.82 Low allow 2026-08-05
dfb[[${98991*97996}]]xca 3.26 Low review 2026-07-29
<th:t="${dfb}#foreach 3.27 Low review 2026-07-29
v3.69451527 2.72 Low review 2026-07-29
v3.6'"()&%<zzz><ScRiPt >qw6V(9512)</ScRiPt> 3.43 Low review 2026-07-29
v3.6&n930603=v971976 2.67 Low review 2026-07-29
v3.6 3.24 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA 126d27c0ac21…
Force block — not fired
Score recovered no
Elapsed 19.4s