Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

PageMo - Sticky notes & Memo in any page

pofjbbchhigcnknnkohmonholngahbgk
Risk Score
6.34
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Productivity
Installs 435
Rating 3.2
Last updated 2022-12-01 (42 months ago)
Manifest version MV3
CSP present ❌ no
Developer crosstime.sun@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Extension abandoned 42 months ago — no security patches for critical DOM/script sinks.
  • Content scripts inject into ALL http/https pages with no CSP; dynamic script creation + innerHTML sinks amplify XSS risk.
  • Privacy policy is Google's own account policy — not scoped to this extension at all; data practices undisclosed.
  • Free-webmail developer (gmail) with no business domain; no verified publisher status.
  • function_constructor (new Function) in bundled app JS with no CSP guard raises code-execution risk.

Evidence

  • abandoned_extension store Last updated December 2022 — 42 months ago; no security maintenance expected.
  • no_csp crx content_security_policy is null; no CSP mitigations for DOM/script sinks.
  • broad_content_scripts manifest content_scripts_matches covers http://*/* and https://*/* — all pages.
  • dynamic_script_creation crx script_src_dynamic in options/js/app.cd3b0707.js; can load remote code without CSP guard.
  • generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, not scoped to this extension.
  • free_webmail_dev store Developer email crosstime.sun@gmail.com; no business domain or verified publisher badge.
  • js_external_hosts crx Extension contacts: goo.gl, ramilaliyev.com, summernote.org, www.buymeacoffee.com, www.google.com (5 hosts).
  • low_rating store Rating 3.2 with 435 installs; no review red flags detected but below-average user satisfaction.

Permissions Breakdown

  • storage low Used to persist sticky notes locally; expected for this category.
  • activeTab low Transient tab access on user action; limited scope.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • webNavigation medium Observes navigation events across browsing; broader than needed for note app.
  • content_scripts http://*/* https://*/* high Injects JS into every page visited; broad reach combined with innerHTML/dynamic script sinks.

Pillar Scores

Permissions3.30
Reputation7.00
Network4.00
Webstore2.50
Maintenance10.00
Privacy10.00
Code Quality6.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:06
Listing SHA 62b6c8a11322…
Force block — not fired
Score recovered no
Elapsed 28.6s