Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Link shortener

oliiideaalkijolilhhaibhbjfhbdcnm
Risk Score
4.71
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 599
Rating 4.2
Last updated 2024-12-05 (20 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@u99.pro
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing (→ +10 Privacy).
  • Uninstall URL hijack and install redirect to u99.pro — classic monetization/tracking shell pattern.
  • Developer name empty and domain looks_throwaway (u99.pro); no verified business identity behind the extension.
  • Stale: 20 months since last update with verified-publisher cap triggered by monetization-domain signal.
  • External JS loaded from tinyurl.com and u99.pro — uncontrolled remote surface with no CSP.

Evidence

  • install_url_hijack crx onInstalled opens https://u99.pro/welcome — 3rd-party redirect on install is a monetization shell indicator.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() called; target null but flag set — uninstall tracking pattern.
  • generic_privacy_policy store Privacy URL is Google Account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — D v3.5 rule: +10.
  • throwaway_domain api threat_intel.developer_domain_info.looks_throwaway==true for u99.pro; no developer name provided.
  • stale_extension store 20 months since last update — Maintenance +6.0; verified-publisher discount capped at -1.0 (monetization domain).
  • external_js_hosts crx JS contacts tinyurl.com and u99.pro; MV3 but no CSP; 2 external hosts from unverified domain.
  • no_developer_name store developer_name is empty string; +1.0 Reputation for missing 'Offered by' identity.
  • verified_publisher_cap store verified_publisher=true but looks_throwaway domain triggers v3.5 invariant 0c/E — discount capped at -1.0.

Permissions Breakdown

  • tabs medium Allows reading tab URLs and metadata; moderate risk for a link-shortener use case.

Pillar Scores

Permissions1.00
Reputation6.00
Network2.00
Webstore7.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:52
Listing SHA b15b43ba91c5…
Force block — not fired
Score recovered no
Elapsed