Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

JSON Formatter

ondecobpcidaehknoegeapmclapnkgcl
Risk Score
3.52
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 10,000
Rating 4.0
Last updated 2026-01-07 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer todd.garland@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Content script runs on <all_urls> — reads/modifies every page the user visits despite only needing JSON pages.
  • Privacy policy is Google's generic account policy: does not scope to this extension, admits data collection and third-party sharing.
  • Developer is a free-webmail (gmail) account with no verified business identity or developer name.
  • No CSP declared on MV3 extension that loads external host jsonlint.com — network surface uncontrolled.
  • Verified-publisher badge present, but policy mismatch and gmail identity limit its assurance value.

Evidence

  • content_scripts_matches=<all_urls> manifest Script injected on every URL; overbroad for a JSON formatter that only needs to act on JSON responses.
  • privacy_policy_generic store Policy URL is myaccount.google.com — Google's own account policy. scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_identity_weak store developer_email=todd.garland@gmail.com, developer_name empty, no business domain. Free-webmail identity.
  • js_external_hosts crx Extension references jsonlint.com as external JS host; no CSP to constrain this surface.
  • verified_publisher=true store Chrome Web Store verified publisher badge present — partial trust signal.
  • cve_findings_raw=[] crx No CVEs detected in bundled libraries.
  • code_findings_raw=[] crx No eval, obfuscation, exfil, or dynamic-script findings detected. obfuscation_score=0.0.
  • months_since_update=5 store Last updated January 7, 2026 — within 3-6 month band, low staleness penalty.

Permissions Breakdown

  • activeTab medium Grants access to current tab's content on user action; moderate risk, scope-limited.
  • content_scripts <all_urls> high Content script injected on every URL gives broad page-read/write capability across all sites.

Pillar Scores

Permissions2.30
Reputation6.50
Network0.00
Webstore1.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA 06fd12965b2d…
Force block — not fired
Score recovered no
Elapsed 19.8s