Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AVG Online Security

nbmoafcmbajniiapeidgficgifbfmjfo
Risk Score
4.12
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 500,000
Rating 4.7
Last updated 2025-09-22 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer browser-extensions@avast.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false and admits data_collection+third_party_sharing without scoping to this extension — triggers +10.0 privacy score per v3.5 rule D.
  • Broad host permissions (https://*/*, http://*/*) with content_scripts on <all_urls> gives full page-read capability across every site visited.
  • No CSP on MV3 extension; while MV3 default is strict, absence noted alongside broad host access.
  • Operator cluster sibling detected (1 sibling under same dev email fingerprint) — minor blast-radius concern.
  • Developer name field empty; identity relies solely on email domain (avast.com) which resolves but is not verified-publisher badged.

Evidence

  • privacy_policy_generic_with_collection_and_sharing api Policy fetched (70184 chars), scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 Rule D: +10.0 privacy.
  • broad_host_permissions manifest host_permissions=[https://*/*, http://*/*] + content_scripts_matches=[<all_urls>]; full cross-site read capability.
  • no_csp manifest content_security_policy=null; MV3 provides strict default but no explicit policy declared.
  • operator_cluster_sibling api sibling_count=1 (gomekmidlodglbbmalcneegieacbdmki) under same dev email fingerprint.
  • developer_identity store developer_name empty; email browser-extensions@avast.com; avast.com resolves, not throwaway, not verified-publisher.
  • no_bad_hosts_no_cve crx bad_host_hits=[], affiliate_hits=[], cve_findings_raw=[], obfuscation_score=0.0 — clean code scan.
  • maintenance_current store Last updated Sep 22 2025; months_since_update=9 → +1.5 maintenance score.
  • install_count_and_rating store 500,000 installs, rating=4.7; no review red flags matched.

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata across all tabs.
  • activeTab low Scoped to user-invoked tab only; low risk standalone.
  • scripting medium Allows programmatic script injection; elevated with broad host_permissions.
  • storage low Local extension data storage only.
  • alarms low Scheduling only; minimal risk.
  • declarativeNetRequest medium Can block/redirect network requests; legitimate for security tool.
  • declarativeNetRequestFeedback low Read-only feedback on matched rules; low incremental risk.
  • https://*/* high Broad host access to all HTTPS sites; enables content script injection everywhere.
  • http://*/* high Broad host access to all HTTP sites; combined with scripting raises capability significantly.

Pillar Scores

Permissions4.50
Reputation4.00
Network2.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Operator Siblings (1)

Other extensions sharing this developer's compound fingerprint:

Scoring History

v3.6 4.12 Medium review 2026-06-16
v3.4-rev 4.11 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA acda579f79e9…
Force block — not fired
Score recovered no
Elapsed 24.6s