Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

hyde — hide the YouTube video player controls

pmkpddhfbiojipiehnejbjkgdgdpkdpb
Risk Score
4.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 80,000
Rating 4.2
Last updated 2025-04-29 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer karmdesai18@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; collects and shares data per that policy.
  • Brand impersonation: extension names YouTube without being a confirmed YouTube/Google product.
  • Free-webmail developer (gmail.com) with no business website; unverifiable identity.
  • 14 months since last update raises supply-chain acquisition risk at 80K installs.
  • No CSP on MV3 is neutral per rubric, but scripting + YouTube content_scripts could be weaponised if extension is sold.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
  • brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=[youtube], confirmed_owner=false, not verified/featured → +2.0 Reputation.
  • free_webmail_developer store developer_email=karmdesai18@gmail.com, no business domain; free-webmail + no verified publisher → Reputation floor 7.5.
  • maintenance_stale store months_since_update=14 → 12-24mo band → +6.0 Maintenance.
  • install_reach store 80,000 installs; >10K +1.0 Webstore; not >100K.
  • no_bad_hosts_no_cve crx bad_host_hits=[], affiliate_hits=[], cve_findings_raw=[] — no threat-intel or CVE findings.
  • code_clean crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[] — no malicious code indicators.
  • content_scripts_scoped manifest content_scripts limited to *.youtube.com/watch?* — narrow, matches stated function.

Permissions Breakdown

  • activeTab low Grants access only to the current tab on user gesture; narrow surface.
  • scripting medium Allows script injection into pages; paired with activeTab keeps it scoped.
  • content_scripts: *.youtube.com/watch?* medium Auto-runs on YouTube watch pages; limited to one domain but covers all watch sessions.

Pillar Scores

Permissions1.50
Reputation7.50
Network0.00
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA 024ecc1b2e9d…
Force block — not fired
Score recovered no
Elapsed 21.9s