Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Click and Clean

mgngmngjioknlgjjaiiamcdbahombpfb
Risk Score
4.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 90,000
Rating 4.2
Last updated 2024-06-25 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer browsernative.apps@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returns HTTP error (fetch_error) — policy is effectively absent for evaluation purposes.
  • Extension is 26 months stale — zombie maintenance risk with 90K installs.
  • install_url_hijack=true: onInstalled opens a third-party URL, a monetization/tracking signal.
  • Developer email is free-webmail (gmail) with no developer name listed; governance accountability low.
  • browsingData permission can clear all local browser data — high-impact if extension is ever compromised or sold.

Evidence

  • privacy_policy_fetch_failed api Privacy policy URL returned HTTPError; policy cannot be evaluated — treated as absent (+10.0 privacy).
  • stale_extension store Last updated June 2024; 26 months since update with 90K installs — zombie maintenance score +8.5.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens a URL — webstore penalty +2.0 applied.
  • verified_publisher_featured store Verified publisher AND featured by Google; discounts applied to reputation, capped per 0c (stale >18mo).
  • free_webmail_dev_no_name store Dev email browsernative.apps@gmail.com, developer_name empty; governance accountability reduced.
  • browsingData_permission manifest browsingData can erase all user browser history, cookies, cache — high-impact if extension compromised.
  • description_promise_mismatch store Description promises download management but 'downloads' permission not declared — mismatch +2.0 webstore.
  • no_cve_no_obfuscation crx code_findings_raw empty, obfuscation_score=0.0, cve_findings_raw empty — code quality clean.

Permissions Breakdown

  • browsingData high Can delete cookies, history, cache, downloads — core function but powerful data-erasure capability.
  • notifications low Shows desktop notifications; limited abuse surface.
  • storage low Stores extension settings locally; low risk.

Pillar Scores

Permissions2.50
Reputation4.50
Network0.00
Webstore3.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-27 19:58
Listing SHA 29971698af38…
Force block — not fired
Score recovered no
Elapsed