Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ethereum Price Ticker

pmdanaagpddigagmcilgcaeedcjhbfpo
Risk Score
6.04
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Other
Installs 73
Rating
Last updated 2023-02-20 (40 months ago)
Manifest version MV3
CSP present ❌ no
Developer mrbuffalo92@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned: 40 months since last update with only 73 installs — no active maintenance.
  • Privacy policy is Google's generic account policy; does not scope to this extension at all.
  • Content script declared on <all_urls> far exceeds stated CoinGecko ticker function.
  • Free-webmail developer (gmail) with no verified business identity or publisher badge.
  • MV3 with no CSP and content script on all URLs raises residual injection risk.

Evidence

  • content_scripts_all_urls manifest content_scripts_matches includes <all_urls> despite extension only needing api.coingecko.com; scope mismatch +1.0 perm.
  • stale_extension store Last updated February 2023; 40 months since update — maintenance pillar 10.0.
  • generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → privacy pillar 10.0.
  • free_webmail_dev store Developer email mrbuffalo92@gmail.com, no business site, no verified publisher → reputation floor 7.5.
  • install_url_hijack crx install_url_hijack=true, target is popup.html (internal) — low severity but flag.
  • no_csp manifest content_security_policy is null; MV3 has strict default but absence noted for context.
  • featured_by_google store is_featured_by_google=true; partial reputation discount applied but free-webmail floor overrides.
  • no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty — code quality clean.

Permissions Breakdown

  • activeTab low Access to currently active tab only; limited scope.
  • https://api.coingecko.com/* low Narrow host permission to CoinGecko API; matches stated function.
  • notifications low Can show desktop notifications; low abuse potential for a ticker.
  • content_scripts <all_urls> high Content script injected on every page despite narrow stated function; scope mismatch.

Pillar Scores

Permissions3.00
Reputation7.50
Network2.00
Webstore4.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA 4ebf453dfdbc…
Force block — not fired
Score recovered no
Elapsed 20.4s