Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Image2Text OCR

phngohjapibeemmkofldldedlbbndbag
Risk Score
3.15
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Screenshot
Installs 5
Rating
Last updated 2026-06-11 (3 months ago)
Manifest version MV3
CSP present ✅ yes
Developer eeriegoesd@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail Gmail dev with no verified business identity and only 5 installs.
  • uninstall_url_hijack flag set — extension registers a 3rd-party uninstall URL.
  • scripting + <all_urls> allows arbitrary JS injection on every site the user visits.
  • new Function() constructor in minified worker lib is a dynamic code execution risk.
  • Privacy policy third_party_sharing=true but data_collection=false and no retention disclosure.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() registered (target null in listing); +3.0 Webstore per rubric.
  • free_webmail_dev store Developer email eeriegoesd@gmail.com with no verified business; Reputation floor applies.
  • broad_host_access manifest <all_urls> host permission paired with scripting; high capability for an OCR tool.
  • function_constructor crx new Function() in lib/worker.min.js; dynamic code execution in minified worker context.
  • small_install_high_perm api Only 5 installs but has HIGH-tier host permission; tail attack surface anomaly.
  • privacy_third_party_sharing api Privacy policy flags third_party_sharing=true with no retention info; +1.0 privacy.
  • js_external_hosts crx External hosts: cdn.jsdelivr.net, extensionpay.com, github.com, stackoverflow.com, developer.mozilla.org.
  • extensionpay_monetization crx ExtensionPay.com in CSP connect-src and content_scripts; paywall monetization layer present.

Permissions Breakdown

  • activeTab low Scoped to user-initiated tab interaction; low blast radius.
  • downloads medium Can write files to disk; potential exfil vector if combined with other signals.
  • storage low Local key-value store; standard for settings persistence.
  • scripting medium Can inject scripts into tabs; elevated risk when paired with <all_urls>.
  • <all_urls> high Broad host access enables script injection and data access on every site.

Pillar Scores

Permissions5.00
Reputation7.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy1.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 12:00
Listing SHA 169a436f4ab5…
Force block — not fired
Score recovered no
Elapsed