Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

FastSave

pnlphjjfielecalmmjjdhjjninkbjdod
Risk Score
6.27
Risk Level: High
Recommendation: 🚫 BLOCK
Category MediaDownloader
Installs 100,000
Rating 3.4
Last updated 2026-04-15 (5 months ago)
Manifest version MV3
CSP present ✅ yes
Developer wilosadi@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but admits data collection + third-party sharing without scoping to this extension — scores maximum privacy risk.
  • cookies + webRequest + scripting + <all_urls> triple combo: can intercept, read, and exfiltrate all session cookies and page content.
  • Developer is anonymous gmail user (no name, no verified business); verified_publisher flag noted but identity unverifiable.
  • install_url_hijack: onInstalled redirects to www.instagram.com — classic install-hijack monetization signal.
  • new Function() constructor in serviceWorker.js enables dynamic code execution; innerHTML sink in popup.js adds DOM-XSS risk.

Evidence

  • cookies+webRequest+scripting+<all_urls> manifest Triple HIGH combo with broad host access; ×1.2 amplifier applied; justified-broad discount applied for MediaDownloader category.
  • install_url_hijack crx chrome.runtime onInstalled opens https://www.instagram.com/ — Webstore +2.0 applied.
  • privacy_policy_admits_3rd_party_no_scope api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) +10.0.
  • free_webmail_developer_no_name store wilosadi@gmail.com, developer_name empty, no business domain → Reputation floor ≥7.5.
  • function_constructor in serviceWorker.js crx new Function() constructor detected — Code Quality +2.5 (function_constructor signal).
  • dom_sink_innerhtml_userctrl in popup.js crx innerHTML from variable; csp_present=true, no CVEs, no eval co-present → +0.5 only.
  • operator_cluster install_url sibling_count=1 api install_url dimension shows 1 sibling; sibling_count=0 on compound so +2.5 not applied; only install_url_hijack scored.
  • verified_publisher with gmail dev and generic policy store verified_publisher=true; monetization_hits empty, no stale — full -3.0 rep discount applied, but floor=7.5 from free-webmail rule dominates.

Permissions Breakdown

  • storage low Stores local extension data; minimal risk.
  • cookies high Access to cookies across all URLs via <all_urls>; sensitive session data exposure.
  • webRequest high Can observe all network requests across all sites.
  • downloads medium Can trigger and manage downloads; moderate risk.
  • tabs medium Access to tab URLs, titles, and navigation events.
  • system.display low Display info only; low impact.
  • declarativeNetRequest medium Can block/redirect network requests declaratively.
  • scripting high Execute scripts on any page via <all_urls>; high capability.
  • <all_urls> (host) high Full access to all websites; broad attack surface.

Pillar Scores

Permissions8.00
Reputation7.50
Network2.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Scoring History

sssiedn17ec364ddp727562726963xsx 5.56 Medium review 2026-09-07
xx pfsssiedxa$"sssiedx 5.78 Medium review 2026-08-08
%22fsssiedxa$'sssiedx 4.61 Medium review 2026-08-08
'fsssiedxasssiedx 6.04 High review 2026-08-08
&#x27;fsssiedxa'sssiedx 6.49 High block 2026-08-08
&#x22;fsssiedxa&#x27;sssiedx 5.49 Medium review 2026-08-08
&#x22;fsssiedxa$'sssiedx 4.52 Medium block 2026-08-08
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 6.01 High review 2026-08-08
fsssiedxa<sssiedx 5.79 Medium review 2026-08-08
<fsssiedxa sssiedx 5.56 Medium review 2026-07-30
<fsssiedxa$"sssiedx 5.59 Medium review 2026-07-30
<fsssiedxa xx psssiedx 4.30 Medium block 2026-07-30
fsssiedxa sssiedx 6.07 High block 2026-07-30
fsssiedxa 5.43 Medium review 2026-07-30
sssieddrubricxsx 5.61 Medium review 2026-07-30
v3.6 6.27 High block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:06
Listing SHA d6df19508326…
Force block — not fired
Score recovered no
Elapsed 30.5s