Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tabs Manager

okeooekaaniggaignhhfeddohlcjadkd
Risk Score
4.97
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 2,000
Rating 3.5
Last updated
Manifest version MV3
CSP present ❌ no
Developer islam.s.elbanna@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • scripting + <all_urls> host permission allows JS injection into every page visited; broad capability for small utility.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • Developer uses free Gmail address with no verified business identity; no domain age data available.
  • last_updated missing — maintenance posture unknown; cannot assess staleness or abandonment risk.
  • Featured badge provides some trust signal, but free-webmail developer with generic privacy policy offsets it.

Evidence

  • broad_host_permissions manifest host_permissions=["<all_urls>"] + scripting permission enables script injection on all sites.
  • generic_privacy_policy store Policy URL is myaccount.google.com/privacypolicy — Google account policy, scope_extension=false, admits data_collection+third_party_sharing.
  • free_webmail_developer store Developer email islam.s.elbanna@gmail.com; domain_age_ct not queried (free webmail); no verified business.
  • featured_by_google store is_featured_by_google=true; provides partial reputation discount.
  • no_csp manifest content_security_policy=null on MV3; MV3 default CSP applies so no MV2 penalty, but no explicit hardening.
  • no_code_findings crx code_findings_raw=[], obfuscation_score=0.0; no malicious code patterns detected in 9 JS files.
  • maintenance_unknown store last_updated empty and months_since_update=null; cannot confirm active maintenance.
  • jquery_3_7_1_no_cves crx jquery@3.7.1 detected; cve_findings_raw empty — no known vulnerabilities at this version.

Permissions Breakdown

  • tabs medium Access to tab URLs, titles, and metadata across all windows.
  • activeTab low Temporary access to the currently active tab on user action.
  • storage low Local extension storage; low direct risk.
  • scripting high Can inject scripts into pages; combined with <all_urls> host permission this is broad capability.
  • <all_urls> (host_permissions) high Grants access to all sites; paired with scripting enables arbitrary JS injection on every page.
  • <all_urls> (content_scripts) high Content scripts run on every URL the user visits, expanding data-access surface.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.00
Webstore1.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA e2162749847c…
Force block — not fired
Score recovered no
Elapsed 22.2s