Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Floating Video with Playback Controls

pnanegnllonoiklmmlegcaajoicfifcm
Risk Score
4.66
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 90,000
Rating 4.2
Last updated 2025-07-22 (13 months ago)
Manifest version MV3
CSP present ❌ no
Developer terrazasterceroa88@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing (Privacy pillar = 10).
  • scripting + <all_urls> host permission allows arbitrary JS injection on every site user visits.
  • new Function() constructor found in 4 JS files including background.js; dynamic code execution risk.
  • Developer is anonymous (no dev name, free Gmail, no business domain); verified/featured status is anomalous.
  • 13 months since last update; moderate staleness for an extension with broad host access.

Evidence

  • generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — Privacy pillar = 10.
  • broad_host_access manifest host_permissions=[<all_urls>] + content_scripts_matches=[<all_urls>] + scripting perm = high-capability combo.
  • function_constructor_multi_file crx new Function() found in background.js, content.js, settings.js, window-content.js — dynamic execution in 4 of 5 JS files.
  • anonymous_developer store developer_name empty; email terrazasterceroa88@gmail.com is free webmail; no business domain.
  • verified_publisher_anomaly store Verified publisher + featured badges present but dev identity is anonymous Gmail; v3.5 invariant 0c does not fully mitigate.
  • maintenance_staleness store 13 months since update (12-24mo band) → Maintenance pillar = 6.0.
  • no_csp manifest csp_present=false on MV3; no additional network penalty (MV3 strict default) but compounds function_constructor risk.
  • no_external_hosts crx js_external_hosts=[] and bad_host_hits=[]; no observed network exfiltration, limiting network pillar to 0.

Permissions Breakdown

  • storage low Stores extension settings locally; low impact.
  • activeTab medium Access to current tab on user action; moderate risk.
  • scripting high Can inject scripts into pages; elevated risk when paired with <all_urls>.
  • tabs medium Can read tab URLs and metadata across all tabs.
  • <all_urls> (host) high Broad host access enables content injection on every site visited.

Pillar Scores

Permissions5.50
Reputation4.00
Network0.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:59
Listing SHA e7cdff30814d…
Force block — not fired
Score recovered no
Elapsed