Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Amazon Result Numbering

nipfdfkjnidadibpbflijepbllfkokac
Risk Score
5.14
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs
Rating
Last updated 2026-03-05 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer 10xprofitio@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — worst-case privacy score.
  • Brand impersonation: developer domain is gmail.com, not amazon.com; confirmed_owner=false.
  • Uninstall URL hijack AND install URL hijack both flagged — classic monetization shell signal.
  • Free-webmail developer email (Gmail) with no verified business identity raises trust concerns.
  • Geo-diverse JS hosts (CN, FR, IE, US — 4 countries) for a simple numbering tool is anomalous.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; developer domain gmail.com, not amazon; confirmed_owner=false.
  • uninstall_and_install_url_hijack crx uninstall_url_hijack=true AND install_url_hijack=true — monetization shell fingerprint.
  • privacy_policy_admits_collection_and_sharing_no_scope api scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar = 10.0 per v3.5 rule D.
  • free_webmail_developer store Developer email 10xprofitio@gmail.com is free-webmail with no verified business publisher badge.
  • geo_diverse_js_hosts crx JS external hosts served from 4 countries (CN, FR, IE, US) for a simple result-numbering extension.
  • external_js_host crx js_external_hosts=['10xprofit.io'] — extension loads JS from developer-controlled remote domain.
  • no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.
  • maintenance_3_to_6_months store months_since_update=5; maintenance score = 1.5.

Permissions Breakdown

  • storage low Persists user settings locally; low standalone risk.
  • *://*.amazon.*/ medium Content-script access across all Amazon TLDs; scoped to stated function but broad geographic reach.

Pillar Scores

Permissions1.30
Reputation7.50
Network2.00
Webstore8.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:42
Listing SHA 9ba633cec2d3…
Force block — not fired
Score recovered no
Elapsed