Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Convert PDF to JPG

oeefjlikahigmlnplgijgeeecbpemhip
Risk Score
4.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 870
Rating 5.0
Last updated 2025-04-17 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@pdf-to-jpg.app
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; data_collection+third_party_sharing admitted without extension-specific disclosure.
  • Uninstall URL hijack detected; install hook opens https://pdf-to-jpg.app/welcome — monetization-shell pattern.
  • Developer domain pdf-to-jpg.app does not resolve — no accountable publisher reachable.
  • No developer name listed; verified badge and featured status cannot compensate for non-resolving dev domain (v3.5 invariant 0c caps discount to -1.0).
  • Stale 16 months with non-resolving dev domain and generic privacy policy — long-term governance risk.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Extension sets uninstall redirect and opens https://pdf-to-jpg.app/welcome on install — monetization-shell signals.
  • privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (rule D).
  • developer_domain_not_resolving api threat_intel.developer_domain_info.resolves=false; caps verified-publisher discount to -1.0 per invariant 0c/v3.5.
  • verified_publisher + featured_by_google store Both badges present but discount capped at -1.0 due to non-resolving domain (invariant 0c).
  • no_developer_name store developer_name is empty string; +1.0 Reputation penalty for missing 'Offered by'.
  • maintenance_stale_16mo store 16 months since update → +6.0 Maintenance (12-24mo band).
  • js_external_hosts crx External JS host pdf-to-jpg.app referenced; domain does not resolve — dead CDN risk.
  • install_count_low_with_hijacks store Only 870 installs yet both install and uninstall URL hooks are active — disproportionate monetization surface.

Pillar Scores

Permissions0.00
Reputation3.50
Network0.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:48
Listing SHA b7e386c1c9b5…
Force block — not fired
Score recovered no
Elapsed