Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MediaPlayer - Video and Audio Player

mgmhnaapafpejpkhdhijgkljhpcpecpj
Risk Score
5.43
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 100,000
Rating 3.9
Last updated 2025-12-10 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer inb.cor@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (scope_extension=false, admits data_collection+third_party_sharing) → +10.0 privacy pillar
  • Install URL hijack (onInstalled opens internal /data/styling/index.html) and uninstall URL hijack flag both set — monetization/tracking shell pattern
  • Developer uses free webmail (gmail) with no business domain; domain_age_ct not queryable; elevated identity risk
  • declarativeNetRequestWithHostAccess can silently redirect or block network requests; no CSP adds surface
  • 12 external JS hosts referenced including ad/analytics-adjacent domains; MV3 no-CSP adds +2.0 network risk

Evidence

  • install_url_hijack crx install_url_hijack=true targeting /data/styling/index.html; onInstalled fires redirect on every install.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target null but flag set — likely survey/ad redirect pattern.
  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email inb.cor@gmail.com; brand_mention.developer_domain=gmail.com; no business website.
  • declarativeNetRequestWithHostAccess manifest HIGH-tier permission enabling network request redirect/blocking without visible host_permissions declared.
  • js_external_hosts_count crx 12 distinct external hosts in JS files including webbrowsertools.com, brightcove.com; country_count=1 (IN).
  • no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit restriction declared.
  • is_featured_by_google store Extension carries Google Featured badge, providing partial reputation credit.

Permissions Breakdown

  • storage low Stores local preferences; low standalone risk.
  • contextMenus low Adds right-click menu items; low risk.
  • notifications low Can push desktop notifications; minor annoyance risk.
  • declarativeNetRequestWithHostAccess high Can redirect/block network requests; broad capability without host_permissions still significant.

Pillar Scores

Permissions3.50
Reputation7.00
Network3.50
Webstore7.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA cbbe8f34da73…
Force block — not fired
Score recovered no
Elapsed 21.6s