Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ghostery AdBlocker for Privacy

mlomiejdfkolichcflejclcbmpeaniij
Risk Score
2.28
Risk Level: Low
Recommendation: ✅ ALLOW
Category Adblock
Installs 2,000,000
Rating 4.7
Last updated 2026-08-05
Manifest version MV3
CSP present ✅ yes
Developer support@ghostery.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host_permissions (http/https/ws/wss *) combined with cookies and webRequest — justified for Adblock but high capability surface.
  • innerHTML sinks in bundled npm libs (hybrids, linkedom, plotly, svg.js) with CSP present but lib-internal XSS risk remains.
  • eval() in @whotracksme/reporting and new Function() in js-yaml — dynamic code execution in bundled dependencies.
  • Privacy policy discloses data collection and third-party sharing; retention documented but sharing scope warrants review.
  • No developer name listed in store; mitigated by verified publisher badge and ghostery.com domain.

Evidence

  • verified_publisher store Ghostery is a verified publisher on Chrome Web Store; ghostery.com resolves, not throwaway.
  • featured_by_google store Extension carries Google Featured badge, reducing reputation risk.
  • broad_host_permissions manifest http/https/ws/wss *://*/* — full site access justified for Adblock category; -1.5 discount applied.
  • code_findings_eval crx eval() in @whotracksme/reporting and new Function() in js-yaml raise dynamic-exec risk in bundled deps.
  • innerHTML_sinks crx 5x dom_sink_innerhtml_userctrl in hybrids, linkedom, plotly, svg.js; CSP present mitigates extension-page XSS.
  • privacy_policy api Scoped policy with collection, retention, third_party_sharing=true disclosed; adequate but sharing warrants scrutiny.
  • no_bad_hosts_no_affiliates api threat_intel shows zero bad_host_hits, affiliate_hits, and monetization_hits.
  • maintenance_current store Updated June 15 2026; 0 months since update — maintenance score 0.

Permissions Breakdown

  • alarms low Schedules background tasks; minimal abuse potential.
  • contextMenus low Adds right-click menu items; low risk.
  • cookies high Can read/write cookies across sites; justified for cookie-blocking adblocker.
  • declarativeNetRequest medium Core adblock mechanism; expected for category.
  • declarativeNetRequestFeedback medium Reads matched rule info; expected for adblock diagnostics.
  • webNavigation medium Monitors navigation events; standard for adblockers.
  • storage low Local config/settings storage.
  • scripting medium Injects scripts; justified for cosmetic filtering.
  • tabs medium Reads tab URLs/titles; standard for adblockers.
  • activeTab low Scoped to user-activated tab only.
  • webRequest high Observes all requests; core adblock need, justified by category.
  • offscreen low MV3 offscreen document; low risk.
  • http://*/* high Broad host access; justified-broad discount applies for Adblock category.
  • https://*/* high Broad host access; justified-broad discount applies for Adblock category.
  • ws://*/* high WebSocket interception; expected for comprehensive adblocking.
  • wss://*/* high Secure WebSocket interception; expected for comprehensive adblocking.

Pillar Scores

Permissions3.50
Reputation2.00
Network0.50
Webstore2.00
Maintenance0.00
Privacy1.00
Code Quality3.00
CVE Exposure0.00

Scoring History

<fsssiedxf$"sssiedx 2.64 Low allow 2026-08-10
%22fsssiedxf xx psssiedx 2.17 Low allow 2026-08-10
%27fsssiedxffdsaxax><!--></ScRiPt>asddsssiedx 2.27 Low allow 2026-08-10
&#x27;fsssiedxf$"sssiedx 2.77 Low allow 2026-08-10
&#x22;fsssiedxf$'sssiedx 3.41 Low review 2026-08-10
fsssiedxf$"sssiedx 2.22 Low allow 2026-08-10
<fsssiedxg$"sssiedx 2.62 Low allow 2026-08-10
<fsssiedxifdsaxax><!--></ScRiPt>asddsssiedx 2.18 Low allow 2026-07-29
fsssiedx<sssiedx 2.44 Low allow 2026-07-29
fsssiedxh sssiedx 2.64 Low allow 2026-07-29
sssieddrubricxsx 2.61 Low allow 2026-07-29
fsssiedxa&#x27;sssiedx 2.29 Low allow 2026-07-28
v3.6 2.28 Low allow 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA 059ae0d2abf4…
Force block — not fired
Score recovered no
Elapsed 32.4s