Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

NFT Airdrop Manager

ohalndninddkaceoghngcpcmeeboppkm
Risk Score
5.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 188
Rating 5.0
Last updated 2024-05-11 (25 months ago)
Manifest version MV3
CSP present ❌ no
Developer dev@nftmagicians.xyz
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • Extension last updated 25 months ago (zombie-tier staleness) with no changelog.
  • innerHTML DOM-XSS sink present in bundled JS with no CSP to mitigate it.
  • Contacts external host airdropmanager.xyz at runtime — unverified third-party backend for an NFT/crypto tool.
  • Unverified developer on .xyz domain with no webstore badges; very low install base (188).

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; scope_extension=false, data_collection=true, third_party_sharing=true.
  • stale_extension store Last updated May 2024; 25 months since update — maintenance pillar 8.5.
  • dom_xss_sink_no_csp crx dom_sink_innerhtml_userctrl in assets/index.html.1679103f.js with csp_present=false elevates code quality risk.
  • external_host_airdropmanager crx js_external_hosts includes airdropmanager.xyz — unverified crypto-adjacent backend; reactjs.org is benign CDN reference.
  • react_16_13_1_bundled crx React 16.13.1 bundled; below 16.14 patch threshold; no CVEs found in cve_findings_raw but version is aging.
  • unverified_developer store verified_publisher=false, is_featured_by_google=false; dev email on .xyz domain; no recognized org.
  • low_install_crypto_niche store Only 188 installs; NFT/airdrop category is high-fraud-risk niche with minimal community vetting.
  • no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP amplifies DOM-sink risk.

Permissions Breakdown

  • storage low Stores local extension state; minimal risk.
  • background low Keeps service worker alive; low risk without host permissions.
  • alarms low Schedules periodic tasks; low standalone risk.

Pillar Scores

Permissions0.90
Reputation5.50
Network2.00
Webstore3.50
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA bf4db19cee69…
Force block — not fired
Score recovered no
Elapsed 22.6s