Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Amazon BSR Fast-View

nhilffccdbcjcnoopblecppbhalagpaf
Risk Score
4.03
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 96
Rating 5.0
Last updated 2026-03-01 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer 10xprofitio@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — triggers maximum privacy score (10.0).
  • Brand impersonation flag: developer domain is gmail.com, not amazon.com; confirmed_owner == false.
  • Free-webmail developer email (gmail) with no verified business identity raises accountability risk.
  • install_url_hijack opens a third-party welcome page on install — minor but indicative of monetization intent.
  • Geo-diversity: JS hosts span 4 countries (CN, FR, IE, US) which is elevated for a simple BSR display tool.

Evidence

  • privacy_policy_generic api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → triggers D-clause (+10.0 privacy).
  • brand_impersonation store brand_mention.is_impersonation=true; developer domain is gmail.com, not amazon; confirmed_owner=false.
  • free_webmail_dev store Developer email 10xprofitio@gmail.com; no verified business website; raises reputation pillar.
  • install_url_hijack manifest install_url_hijack=true; onInstalled opens pages/welcome.html — monetization/tracking intent indicator.
  • geo_diversity crx JS hosts span 4 countries (CN, FR, IE, US); +1.5 network for category not in VPN/Translation/etc.
  • host_permissions_scope manifest 21 Amazon regional TLD host_permissions; content_scripts match Amazon only — consistent with stated BSR function.
  • no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty — no code-level signals detected.
  • maintenance_ok store 5 months since update — within 3-6 month bracket (+1.5 maintenance).

Permissions Breakdown

  • storage low Persists local settings/data; no exfil risk on its own.
  • *://*.amazon.com/* (and 20 regional amazon domains) medium Content-script access to all Amazon storefronts; narrow to stated function but broad across 21 TLDs.

Pillar Scores

Permissions1.30
Reputation6.50
Network1.50
Webstore4.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:41
Listing SHA e27d100fd15e…
Force block — not fired
Score recovered no
Elapsed