Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Privacy Test

pdabfienifkbhoihedcgeogidfmibmhp
Risk Score
6.09
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category PrivacyTool
Installs 400,000
Rating 4.7
Last updated 2024-01-24 (29 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@mixesoft.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
  • management permission can enumerate and control all installed extensions — high privilege for a privacy tester.
  • Privacy policy URL points to the Chrome Web Store listing page itself, not a real policy — functionally no scoped policy.
  • Extension is 29 months stale (last updated Jan 2024) with 400K installs — abandoned at scale.
  • 8 distinct external hosts contacted (api64.com, builtwith.com, ipinfo.io, scan32.com, etc.) — broad network reach for a privacy tool.

Evidence

  • management + privacy permissions manifest management allows disabling other extensions; privacy allows toggling browser privacy settings — both HIGH-tier.
  • privacy_policy_url is CWS listing page store URL resolves to the extension's own store page, not a real privacy policy; scope_extension=false, data_collection=false.
  • 8 external JS hosts in CSP connect-src crx api64.com, builtwith.com, dns.google, ipinfo.io, scan32.com, sitecheck.sucuri.net, www.hotcleaner.com among others.
  • uninstall_url_hijack=true crx chrome.runtime.setUninstallURL() registered; target URL not captured but pattern scores +3.0 webstore.
  • months_since_update=29 store Last updated Jan 2024, 29 months ago; zombie booster applies (>10K installs). Maintenance pillar = 8.5+1.0 capped at 10 → 8.5.
  • verified_publisher + is_featured_by_google store Verified publisher and Google-featured; reputation discounts applied but capped at -1.0 per invariant 0c (stale >18mo).
  • obfuscation_score=0, code_findings_raw=[] crx No obfuscation or malicious code patterns detected across 5 scanned JS files.
  • operator_cluster sibling_count=0, no bad/affiliate/monetization hits api No threat-intel hits; dev domain mixesoft.com resolves and is not throwaway.

Permissions Breakdown

  • activeTab low Scoped to user-initiated tab interaction only.
  • management high Can enumerate and disable/enable other installed extensions — high abuse potential.
  • privacy high Can read and modify browser privacy settings (tracking protection, WebRTC, etc.).
  • scripting medium Can inject scripts into pages; risk scoped by lack of broad host_permissions.
  • storage low Local extension storage only.

Pillar Scores

Permissions7.50
Reputation2.00
Network4.50
Webstore4.50
Maintenance8.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA 2fead4c663ea…
Force block — not fired
Score recovered no
Elapsed 24.3s