Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Image Resizer Extension

pjfbjgmjonkfdjkgplflnaeojcjeoimn
Risk Score
3.29
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 849
Rating 3.1
Last updated 2026-08-01
Manifest version MV3
CSP present ✅ yes
Developer michaellu8@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy hosted on sites.google.com, not scoped to this extension, admits data collection and third-party sharing — scores max privacy risk.
  • Developer uses free Gmail address with no developer name; identity unverifiable despite verified_publisher badge.
  • Extension contacts yandex.com JS host (RU geo) alongside Stripe and PostHog — unexpected for a simple image resizer.
  • new Function() constructor in bundled stripeJS.js; code execution risk if input is attacker-controlled.
  • Privacy policy explicitly states third-party data sharing with no extension-specific scope.

Evidence

  • privacy_policy_generic_with_data_sharing api Policy on sites.google.com: scope_extension=false, data_collection=true, third_party_sharing=true — v3.5(D) triggers +10.0 privacy.
  • developer_identity store developer_email=michaellu8@gmail.com, developer_name empty; free webmail + no business domain.
  • yandex_js_host crx js_external_hosts includes yandex.com (RU); unexpected for image resizer; geo_diversity country_count=3 (CA,RU,US).
  • function_constructor_in_stripe crx new Function() in libs/stripeJS.js; likely Stripe bundle pattern but still a code execution surface.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; reduces reputation risk but does not explain Yandex contact.
  • posthog_analytics crx app.posthog.com and us.i.posthog.com in JS hosts and host_permissions; telemetry collection confirmed.
  • no_developer_name store developer_name field is empty string; +1.0 reputation per rubric.
  • low_install_count store Only 849 installs; blast radius limited, but policy and identity signals remain elevated.

Permissions Breakdown

  • storage low Stores user preferences locally; no cross-site data access.
  • sidePanel low Opens a side panel UI; no privileged data access.
  • host: hqcklghtagnlihrccyqo.supabase.co/* medium Scoped to a specific Supabase backend; data storage/auth endpoint.
  • host: https://us.i.posthog.com/* medium Scoped to PostHog analytics; telemetry sent to third party.

Pillar Scores

Permissions0.60
Reputation3.50
Network3.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:59
Listing SHA 405afee24ef2…
Force block — not fired
Score recovered no
Elapsed