Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

EchoSearch

abclkepfnkmfkhohoogobbekdcdghaoi
Risk Score
6.05
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 3
Rating
Last updated 2026-03-20 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer service@explorads.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search provider silently overridden to blpsearch.com with embedded tracking params (source=ea_ext_yhs_1984, pc=EAES).
  • Uninstall URL hijack enabled — redirects user on removal to 3rd-party destination.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
  • Developer email domain (explorads.com) is an ad-tech operator; extension description explicitly mentions 'analytics tracking'.
  • Tiny install base (3) with HIGH-tier permissions — tail attack surface, possible staged deployment.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets blpsearch.com as default search with tracking params source=ea_ext_yhs_1984_echosearch&pc=EAES.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension registers an uninstall redirect to a 3rd-party URL.
  • ad_tech_developer store Developer email service@explorads.com; expldata.com host in js_external_hosts implies analytics/ad data collection.
  • privacy_policy_unscoped_admits_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy score.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity disclosed in store listing.
  • install_perm_anomaly api Only 3 installs with HIGH-tier permissions (cookies, search override, host_permissions); small_install_high_perm=true.
  • manifest_description_tracking manifest Description explicitly states 'intelligent redirection and comprehensive analytics tracking' confirming data collection intent.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension.

Permissions Breakdown

  • storage low Stores extension state locally; minimal risk alone.
  • cookies high Can read/write cookies on permitted hosts; enables tracking/session hijack.
  • declarativeNetRequest medium Can redirect/block requests; combined with search override amplifies control.
  • chrome_settings_overrides.search_provider (is_default:true) high Silently replaces default search engine; core monetization vector via blpsearch.com.
  • host_permissions: https://*.blpsearch.com/* high Full cookie and request access to the replacement search provider domain.
  • host_permissions: https://*.expldata.com/* high Access to analytics/data collection domain; name implies data exfiltration.

Pillar Scores

Permissions7.50
Reputation7.00
Network2.50
Webstore7.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:59
Listing SHA fa066a76ffaf…
Force block — not fired
Score recovered no
Elapsed