Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

StackOverflow widener

mooeijkhkjholfaebkfjopgidkjeljjk
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 6
Rating
Last updated 2022-05-18 (49 months ago)
Manifest version MV3
CSP present ❌ no
Developer alexei.shamov@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • Extension last updated 49 months ago (>36mo), fully stale/abandoned.
  • Developer uses free Gmail address with no business identity; brand_mention flags StackOverflow impersonation.
  • No CSP (MV3 strict default applies but no explicit policy); +2.0 network penalty for MV2-style absence not applied for MV3, but noted.
  • Only 6 installs and no ratings — unverified, unaccountable micro-publisher.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; mentions 'stackoverflow', developer is not confirmed owner, email is gmail.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
  • maintenance_stale store Last updated May 2022; months_since_update=49 (>36mo) → maintenance pillar 10.0.
  • free_webmail_developer store Developer email alexei.shamov@gmail.com; no business website; developer_domain gmail.com.
  • no_csp manifest content_security_policy=null; MV3 so no +2.0 network penalty, but network base +0 with no external hosts.
  • no_code_findings crx js_files_scanned=0, code_findings_raw=[], obfuscation_score=0.0 — no JS surface observable.
  • very_low_installs store Only 6 installs, 0 ratings; micro-publisher with no accountability signals.
  • content_scripts_scoped manifest content_scripts_matches restricted to stackoverflow.com question paths only; low capability.

Permissions Breakdown

  • content_scripts(*://stackoverflow.com/*) low Scoped solely to stackoverflow.com, matching stated function of widening layout.

Pillar Scores

Permissions0.30
Reputation7.50
Network2.00
Webstore4.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA d15c64b8997c…
Force block — not fired
Score recovered no
Elapsed 19.6s