Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Password Alert

noondiphcddnnabmjcihcjfbhfklnnep
Risk Score
3.78
Risk Level: Low
Recommendation: ✅ ALLOW
Category Security
Installs 400,000
Rating 4.3
Last updated 2025-03-05 (15 months ago)
Manifest version MV3
CSP present ✅ yes
Developer passwordalert-feedback@google.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing (+10.0 privacy pillar).
  • <all_urls> host permission + scripting injects into every page; high-capability surface even from a trusted developer.
  • Months since update is 15 — falls in 12-24mo stale band (+6.0 maintenance); security tool staleness is operationally risky.
  • CSP connect-src allows https://* (broad outbound); acceptable for security tool but noteworthy.
  • Developer is Google (recognized org) and is_featured_by_google=true, substantially mitigating reputation risk.

Evidence

  • recognized_org_developer store Developer email passwordalert-feedback@google.com; domain google.com resolves, not throwaway.
  • is_featured_by_google store Extension marked is_featured_by_google=true; follows recommended practices badge applied.
  • generic_privacy_policy api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
  • broad_host_permission manifest <all_urls> in host_permissions + content_scripts_matches; scripting permission paired — high capability.
  • maintenance_stale store Last updated March 2025; 15 months ago → 12-24mo band = +6.0 maintenance score.
  • csp_connect_broad manifest CSP connect-src https://* allows outbound to any HTTPS host; +2.5 network, offset by security category discount.
  • no_bad_hosts_no_cves crx cve_findings_raw empty, bad_host_hits empty, code_findings_raw empty, obfuscation_score=0.0.
  • capability_gate_check manifest Recognized-org -2.0 discount capped at -1.0 per v2 rule 0b: extension has broad host+scripting (HIGH-impact capability).

Permissions Breakdown

  • identity low OAuth identity access; low risk alone, needed for Google account detection.
  • identity.email medium Reads signed-in user email; core to password-alert function but sensitive PII.
  • notifications low Displays alerts; no data exfil risk.
  • scripting medium Can inject scripts into pages; paired with <all_urls> increases surface.
  • storage low Local config/hash storage; expected for password-hash caching.
  • tabs medium Can read tab URLs; needed for phishing-page detection.
  • <all_urls> (host_permission) high Content script on every URL; required for phishing detection but broad surface.

Pillar Scores

Permissions4.10
Reputation2.00
Network2.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA ec84d52ad8d6…
Force block — not fired
Score recovered no
Elapsed 24.8s