Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Accept all cookies

ofpnikijgfhlmmjlpkfaifhhdonchhoi
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 60,000
Rating 4.4
Last updated 2025-02-23 (16 months ago)
Manifest version MV3
CSP present ❌ no
Developer jeanforan29@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy (scope_extension=false, admits data collection & 3rd-party sharing) — scores maximum privacy risk.
  • scripting + <all_urls> allows arbitrary JS injection into every site the user visits.
  • declarativeNetRequestWithHostAccess can silently block or redirect network traffic on all URLs.
  • Developer uses free Gmail address with no verifiable business identity or domain.
  • 16 months since last update with no CSP; MV3 mitigates some risk but broad host access persists.

Evidence

  • generic_privacy_policy store Policy URL is myaccount.google.com; scope_extension=false, data_collection=true, third_party_sharing=true — D-clause triggers +10.0 privacy.
  • free_webmail_developer store Developer email jeanforan29@gmail.com with no business domain or verified publisher badge.
  • broad_host_permissions manifest host_permissions=[<all_urls>] combined with scripting and declarativeNetRequestWithHostAccess.
  • no_csp crx content_security_policy is null; MV3 enforces strict-ext default but no explicit CSP declared.
  • maintenance_16mo store Last updated February 2025; 16 months stale falls in 12-24mo bracket (+6.0 maintenance).
  • is_featured_by_google store Extension carries Featured badge; applied -2.0 reputation discount.
  • no_bad_hosts_no_cve crx cve_findings_raw=[], bad_host_hits=[], affiliate_hits=[], code_findings_raw=[] — no active malicious signals.
  • external_js_hosts crx js_external_hosts=[chrome.google.com, popper.js.org]; 2 distinct domains, below +1.5 geo-diversity threshold.

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata; moderate risk for a cookie-management tool.
  • storage low Local config/state storage only.
  • declarativeNetRequestWithHostAccess high Can block/redirect network requests across all URLs; high capability.
  • webNavigation medium Observes navigation events on all pages; moderate privacy surface.
  • scripting high Programmatic script injection into any page via <all_urls> host permission.
  • <all_urls> (host) high Grants access to every site the user visits; broad attack surface.

Pillar Scores

Permissions6.50
Reputation6.50
Network2.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA c56ce18f5e41…
Force block — not fired
Score recovered no
Elapsed 22.7s