Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DNS Configuration Manager

opoejijmagmdeeobilcpjnllpmoklnlk
Risk Score
2.43
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 1,000
Rating 3.9
Last updated 2025-07-21 (11 months ago)
Manifest version MV3
CSP present ✅ yes
Developer info@mohammadnasser.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL unreachable (fetch_error) — cannot verify data handling claims.
  • new Function() in bundled test files enables arbitrary code execution if input reaches them.
  • innerHTML user-controlled sink in popup.js is a DOM-XSS vector.
  • Extension 6–12 months stale (Maintenance +3.5); DNS tool with no host perms but unclear update cadence.
  • Unverified solo developer; no verified-publisher badge reduces accountability.

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (ConnectionError); policy scored as inaccessible → +10.0 privacy.
  • function_constructor_in_test_files crx new Function() found in comprehensive-test.js and test-extension.js; appears test scaffolding but bundled in crx.
  • dom_xss_sink crx popup.js assigns user-controlled variable to innerHTML; CSP present but doesn't fully mitigate DOM-XSS.
  • maintenance_stale store months_since_update=11; falls in 6–12mo band → +3.5.
  • no_verified_publisher store verified_publisher=false, not featured; reputation starts 5.0 with no adjustments.
  • low_install_count store Only 1,000 installs; blast radius limited but tail-attack-surface flag not triggered per install_perm_anomaly.
  • js_external_host_dev_domain crx js_external_hosts=['mohammadnasser.com']; single dev-owned domain, no third-party CDN.
  • cve_findings_empty crx No CVEs detected in bundled libraries; CVE pillar=0.0.

Permissions Breakdown

  • storage low Stores DNS config settings locally; low risk.
  • alarms low Periodic background tasks; no data exfil capability on its own.

Pillar Scores

Permissions0.60
Reputation5.00
Network0.00
Webstore0.00
Maintenance3.50
Privacy10.00
Code Quality3.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA fb0b046a6a0e…
Force block — not fired
Score recovered no
Elapsed 23.7s