Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

URL Shortener - TinyURL Extension

mnnjjchefohcoocleiepmdpfhdpgoflk
Risk Score
3.64
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 6,000
Rating 4.4
Last updated 2025-03-12 (15 months ago)
Manifest version MV3
CSP present ✅ yes
Developer dev.bergda@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy, not scoped to this extension — admits data collection and 3rd-party sharing.
  • Developer uses free Gmail account with no verified business identity.
  • Extension is 15 months since last update, slightly stale.
  • scripting permission combined with activeTab could inject content on demand.
  • No rating count visible; install base small (6K) limiting social-proof signal.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
  • free_webmail_dev store Developer email dev.bergda@gmail.com — free webmail, no verified business. Reputation starts 5.0 +1.5 = 6.5.
  • featured_by_google store is_featured_by_google=true; eligible for -2.0 reputation discount but not applied fully due to gmail dev.
  • maintenance_stale store 15 months since update falls in 12-24mo band → +6.0 maintenance score.
  • csp_present_mv3 manifest CSP restricts connect-src to self + tinyurl.com; MV3 default strict. No unsafe-eval/inline.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0 — no malicious code indicators.
  • no_cve_findings crx cve_findings_raw empty; js_libraries_detected empty → CVE pillar 0.0.
  • threat_intel_clean api bad_host_hits, affiliate_hits, monetization_hits all empty; single external host tinyurl.com matches stated function.

Permissions Breakdown

  • activeTab low Only accesses the current tab on user action; low blast radius.
  • scripting medium Can inject scripts into pages; scoped to activeTab limits reach.
  • contextMenus low Adds right-click menu items; no data access on its own.
  • clipboardWrite low Writes shortened URL to clipboard; no read capability.

Pillar Scores

Permissions1.60
Reputation6.50
Network0.00
Webstore0.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA 144f2145ee1c…
Force block — not fired
Score recovered no
Elapsed 20.6s