Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Payment Fee Calculator

mjconefdhjncekilhookekfkfomgiamf
Risk Score
3.56
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs
Rating
Last updated 2026-04-23 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer hello@payable.at
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but does not scope to this extension, admits data collection and third-party sharing — scores maximum privacy risk.
  • No developer name listed; identity accountability limited to email domain payable.at.
  • innerHTML assignment without CSP (MV3 default CSP but no explicit policy) creates DOM-XSS sink in fees.js.
  • No install count available — blast radius unknown; tail-attack surface if distributed later.
  • No rating data; extension trust signals are minimal.

Evidence

  • privacy_policy_scope_extension_false_with_data_collection_and_third_party_sharing api Policy fetched (43676 chars), scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (v3.5 rule D).
  • dom_sink_innerhtml_userctrl crx fees.js assigns innerHTML from variable; no CSP present — elevated to +2.0 per FIX B.
  • no_developer_name store developer_name is empty string; reputation starts at 5.0 +1.0 for missing offered-by.
  • no_installs_no_rating store installs and rating both empty/zero; blast radius and trust signals unknown.
  • mv3_no_explicit_csp manifest MV3 extension; no explicit CSP declared. MV3 default CSP applies — no +2.0 MV2 penalty.
  • threat_intel_clean api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], no throwaway domain, resolves=true.
  • maintenance_recent store Last updated April 23 2026, 2 months ago — maintenance pillar 0.0.
  • cve_findings_empty crx No CVEs found in bundled libraries; cve_pillar_score=0.0.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • activeTab low Temporary access to current tab only on user gesture; limited scope.

Pillar Scores

Permissions0.60
Reputation6.00
Network2.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA 5468299bd856…
Force block — not fired
Score recovered no
Elapsed 20.9s