Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

LookGood Live

mleflnbfifngdmiknggikhfmjjmioofi
Risk Score
3.27
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 5,000
Rating 3.6
Last updated 2026-05-18 (3 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@webcameffects.app
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy, not scoped to this extension; data_collection and third_party_sharing are true.
  • Broad host_permissions (http://*/*, https://*/*) + content_scripts on <all_urls> allow full page read/write on every site.
  • Developer name is blank; no 'Offered by' name visible despite verified-publisher badge.
  • External JS hosts include vuejs.org and webcameffects.app — two non-CDN origins loaded by the extension.
  • Small install base (5,000) with broad host access increases tail-attack-surface concern.

Evidence

  • broad_host_permissions manifest host_permissions include http://*/* and https://*/* plus content_scripts on <all_urls>.
  • generic_privacy_policy store Privacy URL points to myaccount.google.com/privacypolicy — Google's own policy, not extension-scoped.
  • verified_publisher_featured store Extension carries both verified_publisher and is_featured_by_google badges.
  • no_developer_name store developer_name is empty string; no visible 'Offered by' attribution.
  • external_js_hosts crx JS contacts accounts.google.com, fonts.gstatic.com, vuejs.org, webcameffects.app.
  • no_code_findings crx code_findings_raw empty; obfuscation_score 0.0; 5 files scanned cleanly.
  • recently_updated store months_since_update=3; maintenance score 0.
  • no_cve_findings crx cve_findings_raw empty; vue 3.4.13 bundled with no known CVEs flagged.

Permissions Breakdown

  • storage low Persists extension settings locally; no user data exfil on its own.
  • http://*/* high Broad host access to all HTTP sites; enables content-script injection everywhere.
  • https://*/* high Broad host access to all HTTPS sites; same risk surface as http broad access.
  • content_scripts <all_urls> high Content scripts run on every page; combined with broad host = full page read/write.

Pillar Scores

Permissions4.50
Reputation2.00
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:35
Listing SHA 711fa2d8ef48…
Force block — not fired
Score recovered no
Elapsed