Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

JSON Formatter and Viewer

nhkjklblokkpocjeegpnnclbdlaphnfo
Risk Score
4.56
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 289
Rating 4.0
Last updated 2024-04-10 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@seoweb.ee
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Extension stale 26 months — abandoned or unmonitored, prime acquisition/compromise target.
  • content_scripts on <all_urls> injects into every page despite JSON-only stated purpose.
  • innerHTML DOM-XSS sink with no CSP amplifies code-quality risk on all visited pages.
  • new Function() constructor in content.js is a dynamic-execution primitive.
  • Developer domain seoweb.ee does not resolve; no accountable entity reachable.

Evidence

  • content_scripts_broad manifest content_scripts matches <all_urls> — runs on every page visited, disproportionate for a JSON formatter.
  • no_csp manifest content_security_policy is null (MV3 default applies but no explicit hardening declared).
  • dom_xss_sink crx innerHTML assigned from variable in client.DYSQn3o3.js with no CSP mitigation.
  • function_constructor crx new Function('return this') in content.js — dynamic code execution primitive.
  • stale_extension store Last updated April 2024; 26 months since update — maintenance pillar +8.5.
  • dev_domain_dead api threat_intel: seoweb.ee does not resolve — developer uncontactable, accountability gap.
  • external_js_hosts crx 9 external JS hosts referenced (github.com, reactjs.org, etc.) — no bad-host hits confirmed.
  • privacy_policy_third_party_silence store Policy scoped, data_collection true, retention true, but third_party_sharing not addressed (+1.0).

Permissions Breakdown

  • storage low Stores user preferences locally; no cross-origin data exposure.
  • content_scripts:<all_urls> high Content script injected on every site; broad reach even with no host_permissions declared.

Pillar Scores

Permissions3.30
Reputation5.50
Network2.00
Webstore0.00
Maintenance8.50
Privacy1.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA ddc954e49389…
Force block — not fired
Score recovered no
Elapsed 22.6s