Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Minimal Theme for Twitter / X

pobhoodpcipjmedfenaigbeloiidbflp
Risk Score
4.18
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 60,000
Rating 4.5
Last updated 2025-12-20 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@typefully.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — Privacy pillar scores 10.0.
  • brand_mention.is_impersonation=true for 'twitter' and developer_name is empty; +2.0 reputation penalty.
  • code_findings include script_src_dynamic and function_constructor (high-tier signals) plus innerHTML sinks with no CSP.
  • install_url_hijack=true; onInstalled opens third-party URL — monetization/tracking concern.
  • No CSP present (MV3 default enforced but bundled Next.js chunks use dynamic script loading and new Function).

Evidence

  • privacy_policy_admits_data_collection_and_third_party_sharing_without_extension_scope api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0 per v3.5 rule D.
  • brand_impersonation_twitter_no_verified_publisher store brand_mention.is_impersonation=true, verified_publisher=false, is_featured_by_google=true → +1.0 reputation (v3.2 rule 9).
  • install_url_hijack crx install_url_hijack=true, target=null; onInstalled redirects to third-party URL — Webstore +2.0.
  • code_script_src_dynamic_and_function_constructor crx script_src_dynamic → +3.0 code quality; function_constructor → +2.5 code quality per v3 rules.
  • dom_sink_innerhtml_no_csp crx dom_sink_innerhtml_userctrl with csp_present=false triggers +2.0 FIX B (v3 code quality).
  • no_developer_name store developer_name empty → +1.0 reputation (no 'Offered by').
  • featured_by_google store is_featured_by_google=true → -2.0 reputation discount applied.
  • maintenance_3_to_6_months store months_since_update=6 → +1.5 maintenance score.

Permissions Breakdown

  • storage low Stores theme preferences locally; LOW risk, no host or data-exfil capability.
  • content_scripts: twitter.com / x.com medium Runs JS on all Twitter/X pages; scoped to stated function but broad within that domain.

Pillar Scores

Permissions0.60
Reputation5.50
Network2.00
Webstore4.00
Maintenance1.50
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:06
Listing SHA 28e36d88abc9…
Force block — not fired
Score recovered no
Elapsed 32.4s