Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Word Counter - Character/Word Counting Stats

nanlniilojileolplljecnafnjockmac
Risk Score
4.14
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 4,000
Rating 2.4
Last updated 2022-08-05 (46 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@oziku.tech
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection AND third-party sharing but is not scoped to this extension — worst-case policy posture.
  • Content script runs on <all_urls> giving broad page-read capability across all sites.
  • Extension not updated in 46 months (>36mo) — effectively abandoned; supply-chain risk if account compromised.
  • No developer name listed; 'oziku.tech' is unverified identity context.
  • Rating 2.4 signals poor user experience and no community trust signal.

Evidence

  • privacy_policy_admits_data_and_third_party api Classification: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] with no host_permissions; broad inject surface on every page.
  • maintenance_abandoned store Last updated Aug 2022; months_since_update=46 (>36mo) → maintenance pillar 10.0.
  • no_csp manifest content_security_policy is null; MV3 has strict default so no v2 penalty, but no CSP present.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; applied reputation discounts but capped due to stale>18mo.
  • low_rating store Rating 2.4; no rating_count provided so <50-rating boost not confirmed but sentiment negative.
  • js_external_host_own_domain crx js_external_hosts=[www.oziku.tech]; single dev-controlled domain, no bad/monetization hits.
  • cve_findings_empty crx No CVEs found in bundled libs (jquery 3.5.1 has no flagged CVEs in cve_findings_raw).

Permissions Breakdown

  • contextMenus low Adds right-click menu items; no data access or host permissions implied.
  • content_scripts:<all_urls> high Script injected into every page visited; broad reach even with no declared host_permissions.

Pillar Scores

Permissions1.80
Reputation2.00
Network0.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA 365f2ba894b5…
Force block — not fired
Score recovered no
Elapsed 19.7s