Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Netflix Party

mmnbenehknklpbendgmgngeaignppnbe
Risk Score
6.09
Risk Level: High
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 400,000
Rating 4.1
Last updated 2026-07-22 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer customfb8@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: unverified Gmail dev claims Netflix name with confirmed_owner=false.
  • Privacy policy is Google's own generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Broad host access (*://*/*) + scripting permission lets extension read/modify every site the user visits.
  • External JS host 'all.telenetflixparty.com' is a non-Netflix domain suggesting parallel infrastructure; dev is Gmail-only.
  • Free-webmail developer (customfb8@gmail.com), no verified publisher, no business domain — high abandonment/sale risk.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; dev is customfb8@gmail.com, confirmed_owner=false, not verified publisher.
  • generic_privacy_policy store Privacy URL is Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • broad_host_access manifest host_permissions=[*://*/*] + content_scripts on <all_urls> + scripting permission = full read/write on every page.
  • external_non_netflix_host crx js_external_hosts includes all.telenetflixparty.com — unrelated domain controlled by unknown party.
  • free_webmail_developer store Developer email customfb8@gmail.com with numbered alias pattern; no business website or verified publisher badge.
  • dom_xss_sinks crx innerHTML assignments in popup.js and content.js with no CSP; elevated DOM-XSS risk on all visited pages.
  • csp_absent manifest content_security_policy=null; MV3 default applies but no explicit CSP hardening declared.
  • multi_platform_host_access crx External hosts include netflix.com, youtube.com, primevideo.com, jiocinema.com — far beyond stated Netflix Party scope.

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata; moderate risk alone but amplified by broad host access.
  • storage low Local data persistence; low standalone risk.
  • scripting high Programmatic script injection into pages; high risk paired with *://*/* host access.
  • *://*/* high Broad host access — extension can read/modify every site visited by the user.
  • <all_urls> (content_scripts) high Content scripts injected into all URLs — maximum reach for a party-watch tool.

Pillar Scores

Permissions7.20
Reputation9.00
Network4.00
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:45
Listing SHA a105db17c301…
Force block — not fired
Score recovered no
Elapsed