Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Adblock for YouTube™ — best adblocker

ojigagjjcmnbplgdkggkkleckaohppok
Risk Score
4.43
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Adblock
Installs 100,000
Rating 4.8
Last updated 2025-10-29 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer hemantagayen931@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses 'YouTube' trademark in name without being affiliated; confirmed by brand_mention.is_impersonation.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Developer is free-webmail (gmail) with no verified business identity; no way to vet accountability.
  • new Function() constructor detected in background.js — dynamic code execution risk.
  • webRequest + scripting on *.youtube.com gives full request inspection and DOM injection capability.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; YouTube trademark used in title; developer is unaffiliated gmail user.
  • free_webmail_developer store Developer email hemantagayen931@gmail.com; no verified business domain; developer_domain_info=null.
  • privacy_policy_generic store Policy is Google account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
  • function_constructor crx background.js contains new Function() constructor — dynamic code execution identified by AST scan.
  • webRequest+scripting manifest webRequest and scripting both declared with host *://*.youtube.com/* — full request+DOM access on YouTube.
  • no_csp manifest content_security_policy is null; MV3 applies strict default but no explicit CSP declared.
  • installs_100k store 100,000 installs; blast radius significant for a gmail-dev impersonation extension.
  • maintenance_moderate store Last updated October 29 2025; months_since_update=8 (3-6mo band boundary, scored at 6-12mo = 3.5).

Permissions Breakdown

  • storage low Stores extension settings locally.
  • unlimitedStorage low Expands local storage quota; no direct exfil risk.
  • scripting high Can inject scripts into YouTube pages; broad capability within host scope.
  • declarativeNetRequest medium Blocks/redirects network requests; core to adblocker function.
  • webNavigation medium Observes navigation events; can track page transitions on YouTube.
  • webRequest high Reads all request metadata on *.youtube.com; sensitive combined with scripting.
  • *://*.youtube.com/* (host) medium Scoped to YouTube only; justified for YouTube adblocker but enables full page access.

Pillar Scores

Permissions5.50
Reputation8.50
Network0.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

v3.6 4.43 Medium review 2026-06-16
v3.4-rev 5.09 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA 1f7d3fdd0253…
Force block — not fired
Score recovered no
Elapsed 24.8s