Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Direct Search Online

bffkjdkbmldjgfibfhggllfpldoepcld
Risk Score
6.75
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 100,000
Rating 4.8
Last updated 2022-10-05 (47 months ago)
Manifest version MV3
CSP present ❌ no
Developer directsearchonline@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search-provider override sets itself as default engine — persistent search hijacking with 100K users.
  • Abandoned 46 months ago (>36mo stale) with 100K active installs — zombie attack surface.
  • Uninstall URL hijack and install URL redirect to third-party directsearchonline.com page.
  • Free-webmail developer (gmail) with no verified publisher status — low accountability.
  • External JS host mattinastazione.com is unrelated to stated function — unexplained dependency.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets Direct Search Online as default search engine (is_default: true).
  • zombie_extension store Last updated October 2022 — 46 months stale with 100K installs. Triple-stale fingerprint applies.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() present; install redirect to directsearchonline.com/installed.php.
  • gmail_developer store Developer email directsearchonline@gmail.com — free webmail, no verified publisher, no business badge.
  • external_js_host_unknown crx JS contacts mattinastazione.com — unrelated to stated search function; unexplained third-party host.
  • dom_xss_sink crx innerHTML assigned from variable in js/pop.js — DOM-XSS risk, no CSP present (MV3 default only).
  • privacy_policy_adequate api Policy fetched, scoped, data_collection=true, retention=true, third_party_sharing=true — adequate.
  • install_url_hijack crx onInstalled opens https://directsearchonline.com/installed.php?extid= — third-party redirect on install.

Permissions Breakdown

  • storage low Stores local preferences; no direct data exfil path.
  • declarativeNetRequest medium Can intercept/modify network requests via declarative rules.
  • host_permission: https://search.directsearchonline.com/* medium Scoped to own search domain; allows script/fetch on that origin.
  • chrome_settings_overrides.search_provider high Sets itself as default search engine — classic search-hijack vector.

Pillar Scores

Permissions5.00
Reputation7.50
Network3.00
Webstore8.00
Maintenance10.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssiedn842b333edp727562726963xsx 7.64 High block 2026-09-09
v3.6 6.75 High block 2026-08-31

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:34
Listing SHA 52992b0c9a15…
Force block — not fired
Score recovered no
Elapsed