Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Context Menu Search

ocpcmghnefmdhljkoiapafejjohldoga
Risk Score
4.46
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 100,000
Rating 4.5
Last updated 2025-04-24 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer contextmenusearch@ashu.co.in
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy (myaccount.google.com) — not scoped to this extension at all; scores as generic non-scoped policy with data_collection+third_party_sharing admitted.
  • 11 distinct external JS hosts contacted including dodopayments.com (payment processor) and two backend hosts on render/vercel — unusually broad for a context-menu utility.
  • No CSP declared (MV3 so no +2 penalty, but broad network surface with no policy constraint).
  • months_since_update=14 with installs=100k; stale maintenance window increases supply-chain risk.
  • Developer name absent; email on ashu.co.in subdomain; no verified publisher badge despite verified_publisher=true — v3.5 invariant 0c caps discount due to monetization-adjacent host (dodopayments.com).

Evidence

  • privacy_policy_generic store Policy URL is Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.
  • external_hosts_broad crx 11 external JS hosts: dodopayments.com, context-menu-search-backend on render+vercel, plus search engines. >3 distinct domains → +1.5 Network.
  • no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP declared.
  • maintenance_stale store Last updated April 2025; months_since_update=14 → Maintenance +6.0 (6-12mo band).
  • install_url_hijack crx install_url_hijack=true but install_url_target=null — fires onInstalled navigation; target not captured.
  • dodopayments_host crx customer.dodopayments.com in js_external_hosts; payment processor contact from a search utility is anomalous.
  • verified_publisher store verified_publisher=true; discount capped at -1.0 per invariant 0c (monetization_hits path via dodopayments).
  • search_engine_count_3 crx search_engine_count=3 (bing, google, yahoo); detected_category=Productivity not NewTab so C-rule does not apply.

Permissions Breakdown

  • contextMenus low Core function — adds right-click search entries; low privilege.
  • storage low Stores user preferences locally; no exfil risk alone.
  • offscreen low MV3 offscreen document for DOM tasks; limited scope.
  • sidePanel low Displays search results in side panel; UI-only capability.

Pillar Scores

Permissions1.20
Reputation4.00
Network5.00
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA e7c636c6c104…
Force block — not fired
Score recovered no
Elapsed 24.0s