Netflix International
pbbaoiomplacehgkfnlejmibhmbebaal
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Netflix brand impersonation by unverified developer 'shirt' at non-resolving domain shirt.rip.
- Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — worst-case D clause applies (+10).
- declarativeNetRequestWithHostAccess on Netflix domains allows request blocking/redirect of Netflix CDN and main site.
- Developer domain shirt.rip does not resolve, raising accountability concerns.
- No CSP on MV3 extension with broad host access to Netflix domains.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[netflix]; confirmed_owner=false; developer is 'shirt'.
- developer_domain_not_resolving api threat_intel.developer_domain_info.resolves=false for shirt.rip.
- privacy_policy_generic_google store PP is Google's account policy: scope_extension=false, data_collection=true, third_party_sharing=true. v3.5 D clause: +10.
- declarativeNetRequestWithHostAccess_netflix manifest Can intercept/block/redirect requests on netflix.com and assets.nflxext.com.
- no_csp crx csp_present=false on MV3 extension; v2 fix (b) does not add +2 on MV3 but no mitigation present.
- low_install_count store Only 1,000 installs; rating=5 with unknown count — not independently verified trust signal.
- js_external_host_stackoverflow crx js_external_hosts includes stackoverflow.com — benign reference but unusual for production extension.
- cve_findings_empty crx No CVE findings detected; cve_pillar_score=0.0.
Permissions Breakdown
- storage low Local key-value storage; limited direct harm potential.
- declarativeNetRequestWithHostAccess high Can block/redirect network requests on scoped Netflix/nflxext hosts.
- *://assets.nflxext.com/* high Host permission to intercept Netflix CDN assets.
- *://netflix.com/* high Full host access to Netflix — can read page content and modify requests.
- *://www.netflix.com/* high Duplicate full host access to Netflix main domain.
Pillar Scores
Permissions5.50
Reputation8.50
Network2.00
Webstore5.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA
40a9eb8c1dae…
Force block
— not fired
Score recovered
no
Elapsed
21.4s