Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

NFT Insights

mommkganpfnnimcbnkhoeklfidgfbmgm
Risk Score
5.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 8
Rating
Last updated 2023-11-07 (31 months ago)
Manifest version MV3
CSP present ❌ no
Developer nftdevsquad@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Stale extension (31 months since update) — abandoned, unpatched if vulnerabilities emerge.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • Free-webmail developer (gmail) with no verified business identity or domain.
  • No CSP declared (MV3 mitigates somewhat but adds no explicit restriction).
  • new Function() constructor in bundled JS; low-risk in context but elevated by absent CSP.

Evidence

  • stale_extension store Last updated November 2023; 31 months since update — zombie risk.
  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email nftdevsquad@gmail.com — no verified business domain.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
  • function_constructor crx new Function() found in scripts/scss.js — likely bundler artifact but unverifiable without CSP.
  • low_installs store Only 8 installs; no community signal to assess safety or malicious behavior.
  • external_hosts crx Contacts dashboard-api.memeland.com and genesis-api.keungz.com; both NFT-adjacent, no bad-host hits.
  • no_verified_publisher store No verified publisher badge; individual developer with gmail address.

Permissions Breakdown

  • declarativeNetRequest medium Can block/redirect network requests; scoped to ruleset, not arbitrary interception.
  • host_permission: https://genesis-api.keungz.com/teaming/token-info low Narrowly scoped single-endpoint host permission for NFT data lookup.
  • content_scripts: *://opensea.io/* low Scoped to opensea.io only; matches stated function of displaying NFT info.

Pillar Scores

Permissions1.30
Reputation6.50
Network2.00
Webstore0.00
Maintenance8.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA 4f2d62780fc0…
Force block — not fired
Score recovered no
Elapsed 21.4s