Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Default zoom for Google Workspace

nflkcdlimipkgbacnfnhfecjgmojhklo
Risk Score
4.59
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 8,000
Rating 4.9
Last updated 2025-01-18 (17 months ago)
Manifest version MV3
CSP present ❌ no
Developer alvernacchia@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: title/description mentions 'Google' and 'Zoom' but developer is unverified gmail user.
  • Privacy policy is Google's generic account policy — not scoped to this extension; data practices undisclosed.
  • No CSP + 3x innerHTML sinks across JS files raise DOM-XSS risk on Google Workspace pages.
  • Gmail developer with no verified business domain; identity unverifiable.
  • 17 months since last update — approaching stale threshold with no disclosed changelog.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; mentions google+zoom; developer is unverified gmail user, not confirmed owner.
  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's account policy, scope_extension=false, collects+shares data.
  • no_csp crx csp_present=false, MV3; no content_security_policy declared.
  • innerHTML_sinks crx 3 files contain dom_sink_innerhtml_userctrl; no CSP present amplifies DOM-XSS risk per FIX B.
  • free_webmail_developer store developer_email=alvernacchia@gmail.com; no business domain; domain_age_ct not queried (free webmail).
  • maintenance_stale store months_since_update=17; falls in 12-24mo band (+6.0 maintenance score).
  • is_featured_by_google store Extension carries Google Featured badge, provides partial reputation mitigation.
  • no_bad_hosts_no_affiliate crx threat_intel bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no malicious network indicators.

Permissions Breakdown

  • storage low Stores extension settings locally; low risk, standard for zoom/preference extensions.
  • http://*.google.com/ (host_permission) medium Broad Google domain access enables content script injection on all Google subdomains.

Pillar Scores

Permissions1.30
Reputation7.50
Network0.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA 1ad0e26b6a24…
Force block — not fired
Score recovered no
Elapsed 25.5s