Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Simple Color Picker

oekcgbklihkajpddgklkakahiabhcjhm
Risk Score
4.01
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 10,000
Rating 5.0
Last updated 2023-03-22 (39 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@ezhil.dev
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Extension is 39 months stale (>36mo) with 10K installs — prime acquisition/hijack target.
  • Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and third-party sharing.
  • No CSP declared (MV3 default strict, but content_security_policy field is null).
  • Featured badge provides some trust signal but developer is unverified publisher.
  • No permissions declared — minimal capability risk, but stale + bad privacy policy remains a concern.

Evidence

  • maintenance_stale store Last updated March 2023; 39 months since update triggers max maintenance score (+10.0) plus zombie booster (+1.0 >36mo+10K installs), capped at 10.
  • privacy_generic_google_policy store Privacy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 per v3.5 rule D.
  • featured_by_google store is_featured_by_google=true provides -2.0 reputation discount (Follows recommended practices badge).
  • no_permissions manifest permissions[], host_permissions[], content_scripts_matches[] all empty — zero capability risk.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — clean code surface.
  • no_threat_intel_hits api bad_host_hits, affiliate_hits, monetization_hits all empty; developer domain ezhil.dev resolves and not throwaway.
  • operator_cluster_clean api sibling_count=0; no clustered sibling extensions under same fingerprint.
  • no_cve_findings crx cve_findings_raw empty; no bundled vulnerable JS libraries detected.

Pillar Scores

Permissions0.00
Reputation3.00
Network0.00
Webstore1.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA c77671f1febf…
Force block — not fired
Score recovered no
Elapsed 21.2s