Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

nbnhhsh - 能不能好好说话

okepehobneenpbhiendcjcanjodhmcbj
Risk Score
6.56
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Other
Installs 205
Rating 5.0
Last updated 2020-07-13 (73 months ago)
Manifest version MV2
CSP present ❌ no
Developer moonrailgun@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Severely abandoned: MV2 extension last updated 73 months ago, no patches since 2020.
  • <all_urls> content script on every page — high reach, any future compromise affects all browsing.
  • Privacy policy is Google's generic account policy — completely unscoped to this extension, admits data collection and 3rd-party sharing.
  • Free-webmail developer (gmail) with no verified business identity or publisher badge.
  • No CSP on MV2 extension with external JS hosts (lab.magiconch.com, jquery CDN domains) increases injection risk.

Evidence

  • extreme_staleness store Last updated July 2020 — 73 months ago. MV2, no maintenance, zombie extension.
  • broad_host_access manifest <all_urls> in permissions and content_scripts_matches — runs on every page.
  • no_csp_mv2 manifest content_security_policy is null on MV2; +2.0 Network penalty applies per v2 calibration.
  • generic_privacy_policy api Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 rule D).
  • external_js_hosts crx js_external_hosts includes lab.magiconch.com and multiple jquery CDN domains — 5 distinct external registrable domains.
  • free_webmail_dev store Developer email moonrailgun@gmail.com; no verified publisher, no featured badge, no business domain.
  • small_install_high_perm api 205 installs with HIGH-tier permission (<all_urls>); tail_attack_surface=true per install_perm_anomaly.
  • no_bad_hosts_no_cve api bad_host_hits empty, cve_findings_raw empty, obfuscation_score=0, code_findings_raw empty — no active malice detected.

Permissions Breakdown

  • <all_urls> high Broad host access — content script runs on every site the user visits.

Pillar Scores

Permissions6.00
Reputation6.50
Network4.00
Webstore4.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:50
Listing SHA 8b959ff60a85…
Force block — not fired
Score recovered no
Elapsed