Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GreenPanthera Search

bfpmblbobcdklnmfabbolldpjbpkhekn
Risk Score
5.81
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 3
Rating
Last updated 2024-11-29 (21 months ago)
Manifest version MV3
CSP present ❌ no
Developer greenpantherasearch@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack flagged: classic monetization/data-collection shell pattern.
  • Install URL hijack flagged: opens 3rd-party URL on install, monetization signal.
  • Search provider override routes all searches to find.greenpanthera.com.
  • Privacy policy is Google's generic policy — not scoped to this extension; admits collection and 3rd-party sharing.
  • Gmail developer with no business name or verified publisher status; throwaway identity signal.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets default search to https://find.greenpanthera.com/?q={searchTerms}&stream=GreenPanthera
  • uninstall_url_hijack crx uninstall_url_hijack=true; target null but code hooks chrome.runtime.setUninstallURL.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens 3rd-party URL pattern detected.
  • generic_privacy_policy store Privacy URL is Google account policy (479797 chars); scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email greenpantherasearch@gmail.com; no developer name; no verified publisher.
  • stale_extension store 21 months since last update; 6-12mo band does not apply — 18-24mo band applies (+6.0 maintenance).
  • tiny_install_base store Only 3 installs; no rating. Tail-attack-surface anomaly not triggered but zero trust signal.
  • no_csp manifest content_security_policy is null; MV3 default applies so no +2.0 network penalty, but noted.

Permissions Breakdown

  • chrome_settings_overrides.search_provider medium Overrides default search engine to find.greenpanthera.com; medium-risk per rubric v2a.
  • uninstall_url_hijack high Sets uninstall URL; even with null target this is a monetization/tracking pattern.
  • install_url_hijack high Opens URL on install; even with null target signals monetization shell behavior.

Pillar Scores

Permissions3.00
Reputation8.00
Network0.00
Webstore9.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:35
Listing SHA d5d5c7cb02f7…
Force block — not fired
Score recovered no
Elapsed