Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Player

phdogoeljjbggglcgpkiabgdkkncgohe
Risk Score
5.98
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 8,000
Rating 3.9
Last updated 2022-01-07 (53 months ago)
Manifest version MV3
CSP present ❌ no
Developer mathieu.b.gravel@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned: 53 months without update on an extension injected into every page.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Content script runs on <all_urls> giving broad DOM read/write access on every site visited.
  • Gmail developer with no business domain — low accountability.
  • description_promise.is_shell_pattern=true: vague 'video player' shell with broad host injection.

Evidence

  • content_scripts_matches=<all_urls> manifest Content script injected on all URLs despite no declared permissions[] — broad reach.
  • months_since_update=53 store Last updated January 2022; >36 months stale — maintenance pillar maxed.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • dom_sink_innerhtml_userctrl crx innerHTML sink in content_script.js; no CSP present — elevated XSS risk.
  • developer_email=gmail.com store Free-webmail dev email, no business website — reduced accountability.
  • is_shell_pattern=true store description_promise flags shell pattern: generic video-player promise with <all_urls> injection.
  • is_featured_by_google=true store Extension carries Featured badge — partial trust signal, partially offsets reputation.
  • cve_findings_raw=empty crx No CVEs detected in bundled libraries.

Permissions Breakdown

  • content_scripts:<all_urls> high Content script injected on every site — broad DOM access across all origins.

Pillar Scores

Permissions3.50
Reputation6.50
Network0.00
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA feb01afebfa6…
Force block — not fired
Score recovered no
Elapsed 20.1s