Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

DNS Info: Free DNS Lookup

paeldkmpniladakhbjedbjdcephgeboe
Risk Score
4.20
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 145
Rating 5.0
Last updated 2024-12-29 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer jaitrasinfosoft@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false, admits data collection and third-party sharing without scoping to this extension → max privacy pillar score.
  • Free-webmail developer (gmail.com) with no verified business identity raises accountability concerns.
  • No CSP present (MV3 default is strict but csp_present=false noted); innerHTML sink in popup.js is a DOM-XSS risk.
  • Description promises 'recording' but lacks tabCapture/desktopCapture — permission mismatch signal.
  • Extension contacts external host dnsinfo.live; developer domain not verified via threat intel.

Evidence

  • privacy_policy_generic_with_data_collection_and_3p_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 per v3.5 rule D.
  • free_webmail_developer store Developer email jaitrasinfosoft@gmail.com; no verified business domain. Reputation floor applies.
  • dom_sink_innerhtml_userctrl crx popup.js assigns innerHTML from variable; no CSP and no other eval findings → +2.0 (FIX B condition met: csp_present=false).
  • description_promise_mismatch store Description promises recording but extension lacks tabCapture/desktopCapture permissions.
  • external_host_contact crx js_external_hosts: [dnsinfo.live]; developer domain info null in threat_intel.
  • maintenance_stale store months_since_update=18; 3.5 maintenance score (6-12mo bracket). Actually 18mo → +6.0 bracket (12-24mo).
  • no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
  • low_install_count store Only 145 installs; no install_perm_anomaly flagged; blast radius minimal.

Permissions Breakdown

  • tabs medium Can read tab URLs/titles; low standalone risk for a DNS lookup tool.

Pillar Scores

Permissions1.00
Reputation6.50
Network0.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA d1cd53dfa610…
Force block — not fired
Score recovered no
Elapsed 21.9s