Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

IP, DNS & Security Tools | HackerTarget.com

phjkepckmcnjohilmbjlcoblenhgpjmo
Risk Score
3.27
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 10,000
Rating 4.1
Last updated 2024-08-29 (22 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@hackertarget.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension==false and admits data_collection+third_party_sharing — triggers +10.0 privacy pillar per v3.5 rule D.
  • Extension is 22 months stale (6-12mo band: +6.0 maintenance); caps verified-publisher discount at -1.0 per invariant 0c.
  • External JS loaded from getbootstrap.com, github.com, popper.js.org beyond dev's own API domain — raises network surface.
  • No developer name listed in store; only email identity available.
  • Privacy policy on hackertarget.com domain does not scope data handling to this specific extension.

Evidence

  • verified_publisher store Verified publisher badge present; discount capped at -1.0 due to months_since_update=22 (>18mo) per invariant 0c.
  • is_featured_by_google store Extension is featured by Google, supporting legitimacy.
  • privacy_policy_scope_mismatch api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • maintenance_stale store Last updated August 2024; 22 months since update → +6.0 maintenance pillar.
  • external_js_hosts crx CSP connect-src restricted to api.hackertarget.com only; but JS hosts include getbootstrap.com, github.com, popper.js.org.
  • no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; 2 JS files scanned with no malicious signals.
  • no_cve_findings crx cve_findings_raw empty; no bundled vulnerable libraries detected.
  • threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain hackertarget.com resolves and not throwaway.

Permissions Breakdown

  • activeTab low Grants access to current tab only on user action; narrow and appropriate for a lookup tool.

Pillar Scores

Permissions0.30
Reputation2.00
Network1.50
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA dd556b174f6e…
Force block — not fired
Score recovered no
Elapsed 19.7s