Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Microsoft Single Sign On

ppnbnpeolgkicgegkbkbjmhlideopiji
Risk Score
2.54
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Security
Installs 33,000,000
Rating 2.2
Last updated 2024-08-01 (24 months ago)
Manifest version MV3
CSP present ✅ yes
Developer win10acc@microsoft.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • nativeMessaging with recognized publisher but content_script on all HTTPS pages creates broad OS+web surface at 35M installs.
  • Privacy policy fetch failed (HTTP error); policy adequacy cannot be confirmed — scored as unfetched (+10.0 privacy pillar).
  • 22 months since last update approaches stale threshold; large install base amplifies exposure window.
  • Rating of 2.2 is low for a 35M-install Microsoft extension — may indicate functional issues or user dissatisfaction.
  • Content scripts on https://*/* paired with nativeMessaging: if compromised, attacker can read page content and relay to OS.

Evidence

  • nativeMessaging + recognized publisher manifest nativeMessaging declared; native_messaging_check.publisher_recognized=true reduces risk but capability remains HIGH.
  • content_scripts broad host manifest content_scripts_matches=['https://*/*'] — runs on every HTTPS page visited by user.
  • privacy policy fetch failed crx privacy_policy_classification.fetched=false (fetch_error:HTTPError); cannot confirm scope or data handling.
  • developer identity confirmed store brand_mention.confirmed_owner=true, developer_domain=microsoft.com, resolves=true, not throwaway.
  • stale update store Last updated August 2, 2024; months_since_update=22 — approaching 24-month stale band.
  • no CVEs, no bad hosts, no obfuscation crx cve_findings_raw=[], bad_host_hits=[], obfuscation_score=0.0, code_findings_raw=[] — clean code signals.
  • strong CSP manifest CSP: script-src 'self', base-uri 'none', form-action 'none', default-src 'none' — well-locked down.
  • low rating at massive install base store Rating 2.2 with 35M installs; no review red flags matched for malware/redirect, likely functional complaints.

Permissions Breakdown

  • nativeMessaging high Allows communication with native OS apps; broad OS-level capability, recognized publisher mitigates but still high-risk.
  • content_scripts https://*/* high Content script runs on all HTTPS pages — broad page-content access across every site user visits.

Pillar Scores

Permissions3.50
Reputation2.00
Network0.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 2.97 Low review 2026-08-05
v3.6&n971696=v905194 3.04 Low review 2026-08-05
v3.6 2.54 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:06
Listing SHA 118a59b362d8…
Force block — not fired
Score recovered no
Elapsed 20.7s