Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Netflix Helper

mlfdbphlfojgfeepjojcalginhedfpnk
Risk Score
5.73
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 516
Rating 4.8
Last updated 2022-10-06 (44 months ago)
Manifest version MV3
CSP present ❌ no
Developer sarequlbasar@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses Netflix name/brand without being affiliated with Netflix.
  • Privacy policy is Google's generic account policy — not scoped to this extension at all.
  • Extension abandoned for 44 months (last updated Oct 2022); maintenance score 10/10.
  • Free-webmail developer (gmail.com) with no verified business identity.
  • Content script runs on all netflix.com pages with tabs permission — session-data exposure risk if ever compromised.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; confirmed_owner=false; brands_mentioned=[netflix]; developer_domain=gmail.com.
  • generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — D(iv) rule: +10.0.
  • maintenance_abandoned store months_since_update=44; >36 months → maintenance pillar 10.0.
  • free_webmail_dev store sarequlbasar@gmail.com; no business website; reputation floor applies (>=7.5).
  • no_csp manifest content_security_policy=null; MV3 so no +2.0 network penalty, but inline-execution risk unmitigated.
  • external_hosts_ko_fi crx js_external_hosts includes ko-fi.com (donation link); no bad-host hits confirmed.
  • no_code_findings crx code_findings_raw=[]; obfuscation_score=0.0; 5 JS files scanned cleanly.
  • stale_mv3_triple_fingerprint store >24mo stale + MV3 (no CVEs, so v2 triple-stale only applies to MV2); no CVEs; partial stale signal only.

Permissions Breakdown

  • storage low Stores local extension settings; no cross-origin data exposure.
  • tabs medium Can read tab URLs/titles; limited risk but broader than activeTab.
  • *://*.netflix.com/ (host) medium Content access scoped only to netflix.com; matches stated function.

Pillar Scores

Permissions2.30
Reputation8.00
Network0.00
Webstore4.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA e748cd5493d8…
Force block — not fired
Score recovered no
Elapsed 22.2s