Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Popup Blocker

pecjjeljffnplfcclbbbklkpcbbkchdk
Risk Score
5.58
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Adblock
Installs 7,000
Rating 4.4
Last updated 2022-09-15 (45 months ago)
Manifest version MV3
CSP present ❌ no
Developer oluminousapps@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned: 45 months since last update — extension may be unpatched or available for acquisition.
  • Privacy policy is Google's generic policy; not scoped to this extension, admits data collection and 3rd-party sharing.
  • Free-webmail developer (gmail) with no verified business identity or domain.
  • Description promises popup/ad-blocking but lacks declarativeNetRequest/webRequest — possible capability mismatch.
  • MV3 with no CSP declared; while MV3 defaults are stricter, absence of explicit CSP is a minor hardening gap.

Evidence

  • maintenance_stale store Last updated September 2022; 45 months elapsed — deepest stale bracket (+10.0).
  • privacy_policy_generic store Policy is Google's own account policy: fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 (v3.5 rule D).
  • reputation_free_webmail manifest Developer email oluminousapps@gmail.com; no business domain; free-webmail penalty applied.
  • description_permission_mismatch store description_promise.mismatches: promises ad-blocking but lacks declarativeNetRequest/webRequest (+2.0).
  • is_featured_by_google store Extension carries Featured badge; applied -2.0 to reputation.
  • no_bad_hosts_no_cve crx bad_host_hits=[], cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0 — clean scan.
  • network_mv3_no_csp manifest MV3 with content_security_policy=null; no external JS hosts; +2.0 network for no CSP on MV2 rule not triggered (MV3).
  • operator_cluster_clean api sibling_count=0; no affiliate/monetization hits; install_url_hijack=false; uninstall_url_hijack=false.

Permissions Breakdown

  • activeTab low Only active tab on user gesture; limited scope.
  • storage low Local settings persistence; no network exfil path observed.
  • tabs medium Can read tab URLs and titles across all open tabs.
  • contextMenus low UI surface only; no data access.

Pillar Scores

Permissions1.30
Reputation6.50
Network2.00
Webstore4.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA a8b0e2a32efd…
Force block — not fired
Score recovered no
Elapsed 21.5s