Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Recipe Reader & Grocery Finder | Ceres Cart

nckacfgoolkhaedphbknecabckccgffe
Risk Score
3.73
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Shopping
Installs 8,000
Rating 5.0
Last updated 2026-07-01
Manifest version MV3
CSP present ❌ no
Developer contact@cerescart.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own account policy — not scoped to this extension; data collection admitted with no extension-specific disclosure.
  • Content scripts injected on ALL http/https origins despite Shopping-tool claim; broad DOM access on every site visited.
  • Dynamic <script> creation and new Function() constructor present in bundle — no CSP to constrain dynamic code execution.
  • No developer name listed despite verified-publisher status; identity accountability gap.
  • External JS hosts include react.dev and www.i18next.com — third-party origin contact without CSP guard.

Evidence

  • broad_content_scripts manifest content_scripts_matches includes http://*/* and https://*/* — full-web DOM injection beyond stated grocery/recipe scope.
  • privacy_policy_generic store Privacy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — v3.5-D applies → +10.
  • dynamic_script_and_function_constructor crx script_src_dynamic + function_constructor in SettingsScreen.js and CountrySelector.js; no CSP to restrict execution.
  • no_csp manifest content_security_policy is null; MV3 default CSP applies but dynamic script creation still flagged.
  • verified_publisher_featured store Extension is verified and featured by Google; discounts applied but capped at floor 2.0 for reputation.
  • external_js_hosts crx 6 external hosts: cerescart.com, nominatim.openstreetmap.org, react.dev, www.amazon.com, www.i18next.com, www.kroger.com.
  • no_developer_name store developer_name is empty string despite verified publisher badge — accountability gap.
  • no_bad_hosts_no_monetization api threat_intel shows no bad_host_hits, monetization_hits, or affiliate_hits; domain resolves and is not throwaway.

Permissions Breakdown

  • storage low Local data persistence; low abuse potential alone.
  • tabs medium Can read tab URLs/titles across all open tabs.
  • content_scripts: http://*/* + https://*/* high Broad content-script injection on all HTTP/HTTPS sites — full page DOM access everywhere.

Pillar Scores

Permissions4.50
Reputation2.00
Network2.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-08 14:01
Listing SHA 85bc5428b53e…
Force block — not fired
Score recovered no
Elapsed