Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

PDF Viewer

oemmndcbldboiebfnladdacbdfmadadm
Risk Score
3.55
Risk Level: Low
Recommendation: ✅ ALLOW
Category ReaderMode
Installs 1,000,000
Rating 3.3
Last updated 2024-10-28 (22 months ago)
Manifest version MV3
CSP present ✅ yes
Developer rob@robwu.nl
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • webRequest + declarativeNetRequestWithHostAccess + <all_urls>: broad traffic interception capability on every site.
  • 20 months since last update — stale for a high-reach extension with 1M installs.
  • install_url_hijack flag set (target null): onInstalled behavior warrants manual verification.
  • Developer name blank; identity relies solely on verified publisher badge and robwu.nl domain.
  • Rating 3.3 may reflect user dissatisfaction; no review red-flags detected but context unknown.

Evidence

  • verified_publisher + featured store Extension carries both verified publisher badge and is_featured_by_google; strong legitimacy signals.
  • broad_permissions manifest webRequest + declarativeNetRequestWithHostAccess + <all_urls> justified for PDF proxy/intercept function.
  • maintenance_stale store Last updated October 2024; 20 months since update triggers +6.0 maintenance score.
  • install_url_hijack crx install_url_hijack=true but target=null; likely benign welcome page but flagged for review.
  • code_quality_clean crx code_findings_raw empty, obfuscation_score 0.0, no CVEs, CSP present with strict self-only script-src.
  • privacy_policy api Policy fetched, scoped to extension, no data collection declared, no third-party sharing; retention not stated.
  • threat_intel_clean api No bad hosts, no affiliate hits, no monetization hits; developer domain robwu.nl resolves and not throwaway.
  • operator_cluster api sibling_count=0; no related suspicious extensions under same fingerprint.

Permissions Breakdown

  • alarms low Scheduling only; no data access.
  • declarativeNetRequestWithHostAccess high Can intercept/redirect network requests across all URLs.
  • webRequest high Observes all HTTP traffic; high data-exposure surface.
  • tabs medium Access to tab URLs and metadata.
  • webNavigation medium Monitors navigation events across all tabs.
  • storage low Local extension data only.
  • <all_urls> (host_permission) high Broad host access enables content script injection on every page.
  • content_scripts file://*/* http://*/* https://*/* high Content scripts run on all pages; paired with <all_urls>.

Pillar Scores

Permissions5.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance6.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00

Scoring History

%22fsssiedxa sssiedx 3.27 Low review 2026-08-13
&#x27;fsssiedxa$'sssiedx 3.17 Low review 2026-08-13
fsssiedxa<sssiedx 3.13 Low review 2026-08-13
<fsssiedxi xx psssiedx 3.38 Low review 2026-08-11
<fsssiedxi&#x27;sssiedx 3.10 Low review 2026-08-11
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.01 Low review 2026-08-11
<fsssiedxa&#x27;sssiedx 3.14 Low review 2026-08-11
fsssiedx<sssiedx 2.96 Low review 2026-08-11
sssieddrubricxsx 3.17 Low review 2026-07-31
v3.6 3.55 Low allow 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA 0305270b7fb6…
Force block — not fired
Score recovered no
Elapsed 22.5s