Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Netflix Party is now Teleparty

oocalimimngaihdkbihfgmpkcpnmlaoa
Risk Score
3.74
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 9,000,000
Rating 4.1
Last updated 2026-08-06
Manifest version MV3
CSP present ✅ yes
Developer team@teleparty.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false + data_collection=true + third_party_sharing=true → admits broad data sharing without extension-specific scoping.
  • Brand impersonation flag: 'netflix' mentioned, confirmed_owner=false, is_impersonation=true; developer is not Netflix.
  • innerHTML DOM-XSS sinks present across 20 content scripts injected into streaming platform pages.
  • Privacy policy hosted on netflixparty.com (prior domain), not current teleparty.com; no retention disclosure.
  • No developer name listed; 12 external JS hosts including posthog analytics and legacy netflixparty.com endpoint.

Evidence

  • privacy_policy_broad_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0 (v3.5 rule D).
  • brand_impersonation store brand_mention.is_impersonation=true, brands=['netflix'], confirmed_owner=false, verified_publisher=true → +1.0 Reputation.
  • dom_xss_sinks crx 20 files contain dom_sink_innerhtml_userctrl; CSP present (csp_present=true) so +0.5 per finding, total +0.5 Code Quality (single bucket).
  • verified_publisher store verified_publisher=true; -3.0 Reputation base. No monetization/CVE/stale triggers so full discount applies.
  • external_hosts_count crx 12 distinct external JS hosts including us.i.posthog.com (analytics) and legacy wptony1.netflixparty.com; >3 domains → +1.5 Network.
  • installs_high store 10,000,000 installs → +1.0+1.0+0.5 Webstore; partially offset by no bad-host/affiliate/monetization hits.
  • no_developer_name store developer_name is empty string → +1.0 Reputation (no 'Offered by' name).
  • privacy_policy_domain_mismatch store Privacy policy URL is netflixparty.com/privacy, not teleparty.com; no retention clause; -2.0 verified-publisher discount not applicable to privacy scope failure.

Permissions Breakdown

  • activeTab low Grants access only to the current tab on user action; scoped and low-risk.
  • storage low Local data persistence; no cross-origin data exposure.
  • scripting medium Allows dynamic script injection into pages; medium risk but limited by activeTab scope.
  • alarms low Timer/scheduling API; no data access.

Pillar Scores

Permissions1.60
Reputation5.00
Network2.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

<fsssiedxa$'sssiedx 3.27 Low review 2026-08-15
dfb{{98991*97996}}xca 3.08 Low review 2026-08-05
v3.6&n998352=v915771 2.05 Low review 2026-08-05
fsssiedxdfdsaxax><!--></ScRiPt>asddsssiedx 3.01 Low review 2026-07-30
fsssiedxd'sssiedx 3.26 Low review 2026-07-30
sssieddrubricxsx 3.11 Low review 2026-07-30
v3.6 3.74 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA f1f971053b41…
Force block — not fired
Score recovered no
Elapsed 30.5s