Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Night Shift

ocginjipilabheemhfbedijlhajbcabh
Risk Score
2.59
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Accessibility
Installs 70,000
Rating 4.5
Last updated 2026-04-11 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer kaigernipired@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing without scoping to this extension — scores maximum privacy risk.
  • Broad <all_urls> host_permissions paired with scripting allows content injection on every visited site.
  • new Function() constructor found in all 4 JS files — dynamic code execution risk across the entire extension.
  • Developer email is free webmail (gmail) with no developer_name listed; identity unverifiable.
  • No CSP defined (MV3 default enforced, but csp_present==false raises residual code-exec risk alongside function_constructor findings).

Evidence

  • privacy_policy_admits_collection_and_third_party_sharing_no_scope api privacy_policy_classification: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (D rule).
  • function_constructor_in_all_js_files crx new Function() detected in background.js, content.js, options.js, popup.js → +2.5 code quality.
  • broad_host_access_with_scripting manifest <all_urls> host_permissions + scripting permission enables injection on all sites; justified-broad discount applied for Accessibility category.
  • verified_publisher_and_featured store verified_publisher=true, is_featured_by_google=true; reputation discounts applied (-3.0, -2.0).
  • free_webmail_developer_email_no_name store kaigernipired@gmail.com; developer_name empty. +1.5 reputation (free webmail, no business website verifiable).
  • no_cve_findings api cve_findings_raw is empty; CVE pillar = 0.0.
  • no_bad_host_monetization_affiliate_hits api threat_intel shows no bad_host_hits, monetization_hits, or affiliate_hits.
  • months_since_update_4 store Last updated April 11 2026; 4 months → maintenance +1.5.

Permissions Breakdown

  • storage low Stores user preferences locally; low risk.
  • scripting medium Allows dynamic script injection into pages; medium risk on its own.
  • tabs medium Can read tab URLs and metadata; moderate risk.
  • <all_urls> (host) high Broad host access enables content injection on every site visited.

Pillar Scores

Permissions4.50
Reputation3.00
Network0.00
Webstore1.00
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:57
Listing SHA e0b6943ad3f4…
Force block — not fired
Score recovered no
Elapsed