Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sticky Notes 3.8 - Super Quick & Personal

plpdjbappofmfbgdmhoaabefbobddchk
Risk Score
4.01
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 100,000
Rating 4.5
Last updated 2024-09-24 (21 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@ukiv.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension==false and data_collection==true; does not scope to this extension.
  • 21 months since last update — approaching stale threshold with installs >100K.
  • Uninstall URL hijack flag set (uninstall_url_hijack=true); target unknown.
  • Install URL hijack flag set (install_url_hijack=true); target unknown.
  • No CSP on MV3 extension; innerHTML DOM-XSS sink present in utility.js.

Evidence

  • verified_publisher + featured store Extension is verified publisher AND featured by Google; reputation discounts applied (floor 2.0).
  • privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=false → +9.0 privacy.
  • months_since_update=21 store Last updated Sep 2024; 21 months → +6.0 maintenance pillar (12-24mo band).
  • install_url_hijack + uninstall_url_hijack crx Both install and uninstall URL hijack flags true; targets null — cannot assess destination.
  • dom_sink_innerhtml_userctrl + no_csp crx innerHTML sink in utility.js with csp_present=false → elevated DOM-XSS risk (+2.0 code).
  • function_constructor in sentry lib crx new Function() in sentry.7.13.0.dist.js — standard Sentry pattern, low additional risk.
  • js_external_hosts count crx 12 external hosts including Firebase, Cloud Functions, api.npoint.io, storage.googleapis.com; >3 distinct domains.
  • no_csp_mv3 manifest content_security_policy is null on MV3; default sandbox applies but no explicit hardening.

Permissions Breakdown

  • storage low Standard local data persistence for notes; expected for this category.
  • identity medium Can access Google identity tokens; elevated risk if misused for auth exfil.
  • system.display low Read display info for positioning UI; low harm potential.

Pillar Scores

Permissions1.60
Reputation2.00
Network3.50
Webstore4.00
Maintenance6.00
Privacy9.00
Code Quality3.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA 02da2c540bf6…
Force block — not fired
Score recovered no
Elapsed 23.8s