Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Lingopie: Learn Languages With TV Shows & Movies

okpndnhlmanejgfjlkpmgnebmeehakik
Risk Score
4.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 50,000
Rating 4.3
Last updated 2026-05-28 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@lingopie.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension at all; admits data collection and third-party sharing.
  • install_url_hijack=true: onInstalled opens a third-party URL.
  • Bundled facebookSDK.js with innerHTML DOM-XSS sink and hex-obfuscation; no CSP to mitigate.
  • No developer name listed; support email only.
  • Content scripts run on Netflix and Disney+ — high-value sites exposed to any SDK vulnerability.

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
  • install_url_hijack crx install_url_hijack=true; target=null. Extension opens third-party URL on install.
  • dom_sink_innerhtml_userctrl crx facebookSDK.js: innerHTML assigned from variable with no CSP guard — DOM-XSS risk.
  • no_csp manifest content_security_policy=null on MV3; amplifies DOM-XSS sink risk in bundled SDK.
  • no_developer_name store developer_name is empty string; reduces accountability.
  • facebook_sdk_bundled crx facebookSDK.js contacts developers.facebook.com and www.facebook.com — third-party telemetry on streaming sites.
  • content_scripts_major_platforms manifest Scripts injected into Netflix and Disney+ — high-value targets for any SDK compromise.
  • obfuscation_hex crx hex_string_density in facebookSDK.js; obfuscation_score=0.17 (below 0.2 threshold but present).

Permissions Breakdown

  • storage low Local key-value store; no cross-site reach.
  • activeTab low Transient access to current tab only on user gesture.
  • content_scripts: https://*.disneyplus.com/*, https://*.lingopie.com/*, https://*.netflix.com/* medium Script injection on major streaming platforms; scoped but high-value sites.

Pillar Scores

Permissions1.30
Reputation5.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA e17d6b0d3d83…
Force block — not fired
Score recovered no
Elapsed 23.0s