Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

NanoInfluencer.ai - Audience Analytics & Find Similar Influencer

oenijgdfkimddokafknnoedmenkdakeb
Risk Score
3.54
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 10,000
Rating 5.0
Last updated 2026-05-20 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@nanoinfluencer.ai
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection + third-party sharing but is NOT scoped to this extension (v3.5 Rule D: +10.0 privacy).
  • Content scripts injected on *://*/* gives broad cross-site reach despite low declared permissions.
  • No CSP on MV3 extension; Amplitude telemetry hosts contacted without policy scoping.
  • Developer name empty; identity accountability relies solely on verified publisher badge.
  • AI/analytics extension processing page content across all sites raises data-exfil concern.

Evidence

  • content_scripts_matches includes *://*/* manifest Extension injects content scripts on every website, giving broad cross-site page access.
  • privacy_policy: data_collection=true, third_party_sharing=true, scope_extension=false crx Policy admits collection + 3rd-party sharing without scoping to this extension → Privacy +10.0 (v3.5 Rule D).
  • verified_publisher=true, is_featured_by_google=true store Both badges present; Reputation floor applied at 2.0.
  • js_external_hosts: api.eu.amplitude.com, api2.amplitude.com crx Only Amplitude telemetry endpoints; no bad-host hits. Network risk low.
  • cve_findings_raw empty, code_findings_raw empty, obfuscation_score=0.0 crx No CVEs, no dangerous code patterns, no obfuscation detected.
  • months_since_update=1 store Updated very recently; maintenance risk negligible.
  • no CSP present manifest MV3 extension lacks explicit CSP; Amplitude hosts not constrained by policy.
  • developer_name empty store No 'Offered by' display name; identity relies on verified email domain only.

Permissions Breakdown

  • storage low Stores local extension state; no cross-site risk on its own.
  • activeTab medium Grants transient access to current tab on user action; limited scope.
  • sidePanel low UI surface only; no data-access capability by itself.
  • content_scripts *://*/* high Injected into ALL websites; broad reach for an AI analytics tool.

Pillar Scores

Permissions3.50
Reputation2.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA ff92d2ab1e1d…
Force block — not fired
Score recovered no
Elapsed 20.6s