Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shade Dark Mode

mkeimkkbcndbdlfkbfhhlfgkilcfniic
Risk Score
5.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Accessibility
Installs 40,000
Rating 4.4
Last updated 2025-02-19 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer cherishago6062@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • scripting + <all_urls> allows arbitrary JS injection into every visited page.
  • Gmail developer with no business identity; no domain-age signal; unverified publisher.
  • Extension contacts 4 external hosts (GA, GitHub, npms.io, Google Fonts) with no CSP.
  • 16 months since last update with broad host permissions still active.

Evidence

  • host_permissions_all_urls manifest <all_urls> grants scripting access to every site the user visits.
  • privacy_policy_generic_google store Policy is myaccount.google.com generic page; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email cherishago6062@gmail.com; no business domain; unverified publisher.
  • no_csp crx content_security_policy is null; MV3 default applies but no explicit restriction on external calls.
  • external_hosts crx Contacts fonts.googleapis.com, github.com, npms.io, www.google-analytics.com at runtime.
  • google_analytics_telemetry api monetization_hits lists google-analytics.com; only telemetry tier, not adtech.
  • maintenance_stale store Last updated Feb 2025; 16 months since update — in 6-12 month band.
  • is_featured_by_google store Extension carries Google Featured badge, partially offsetting reputation risk.

Permissions Breakdown

  • alarms low Schedules periodic tasks; minimal risk in isolation.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • scripting medium Injects scripts into pages; paired with <all_urls> raises capability.
  • storage low Stores extension settings locally; minimal risk.
  • <all_urls> high Host permission covering every site; broad reach for script injection.

Pillar Scores

Permissions5.50
Reputation7.00
Network3.00
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA 5ff1862ee386…
Force block — not fired
Score recovered no
Elapsed 19.4s