Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Enhancer for YouTube™

ponfpcnoihfmfllpaingbgckeeldkhle
Risk Score
1.73
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 1,000,000
Rating 4.7
Last updated 2026-07-15 (1 months ago)
Manifest version MV?
CSP present ❌ no
Developer webmaster@mrfdev.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — worst-case privacy posture.
  • Brand-mention impersonation: 'YouTube' in name/title without confirmed owner; verified publisher mitigates but doesn't eliminate risk.
  • manifest_source is html_fallback — actual permissions unverifiable; true capability surface unknown.
  • Developer name field empty; reduces accountability signal despite verified publisher badge.
  • 1M+ installs with broad YouTube access creates significant data-reach if policy terms are exercised.

Evidence

  • privacy_policy_admits_collection_and_sharing_no_scope api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D: +10.0 privacy pillar.
  • brand_impersonation_youtube store brand_mention.is_impersonation=true, brands=['youtube'], confirmed_owner=false. Verified publisher → +1.0 reputation.
  • verified_publisher_and_featured store verified_publisher=true AND is_featured_by_google=true; apply -3.0 reputation discount, floor 2.0.
  • manifest_html_fallback_1m_installs store manifest_source=html_fallback AND installs=1,000,000 → v3.5 rule B: +3.0 webstore.
  • install_count_over_1m store +1.0 (>100k) +1.0 (>1M) webstore; -0.5 popularity-trust offset (rating 4.7 >=4.0).
  • no_bad_hosts_no_monetization_no_affiliates api threat_intel: bad_host_hits=[], monetization_hits=[], affiliate_hits=[] — no network threat signals.
  • recently_updated store months_since_update=3; maintenance pillar = 0.0.
  • no_code_findings_obfuscation_zero crx code_findings_raw=[], obfuscation_score=0.0, js_files_scanned=0 (html_fallback); code quality = 0.0.

Permissions Breakdown

  • manifest_source:html_fallback medium No CRX available; permissions inferred from store listing only — exact capabilities unknown.

Pillar Scores

Permissions1.50
Reputation3.50
Network0.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

<fsssiedxi 3.02 Low review 2026-08-11
<fsssiedxi&#x22;sssiedx 2.88 Low review 2026-08-11
<fsssiedxi$"sssiedx 2.69 Low review 2026-08-11
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 1.62 Low review 2026-08-11
<fsssiedxa"sssiedx 3.42 Low review 2026-08-11
<fsssiedxa 3.29 Low review 2026-08-11
<fsssiedxa$'sssiedx 3.14 Low review 2026-08-11
fsssiedx<sssiedx 3.12 Low review 2026-08-11
dfb__${98991*97996}__::.x 3.01 Low review 2026-08-05
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 3.22 Low review 2026-08-05
v3.6&n942939=v960815 3.11 Low review 2026-08-05
fsssiedxa sssiedx 3.26 Low review 2026-07-28
fsssiedxa"sssiedx 3.09 Low review 2026-07-28
fsssiedxa&#x27;sssiedx 2.87 Low review 2026-07-28
sssieddrubricxsx 3.28 Low review 2026-07-28
v3.6 1.73 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA 700bb7ab1df2…
Force block — not fired
Score recovered no
Elapsed 21.5s