Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Change Default Search Engine

cfikbclbljhmmokgdokgjhnpinnmihkp
Risk Score
5.06
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 7,000
Rating 4.3
Last updated 2026-07-09 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer jeff38399green@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override routes all user queries through developer-controlled default-search.site with no scoping disclosure.
  • Host permission to 'ext-ads-mvp.captain-products.workers.dev' indicates ad-serving infrastructure bundled into a search-changer.
  • Privacy policy is Google's own generic policy — does not scope to this extension; admits data collection and 3rd-party sharing.
  • Bundled jquery@2.1.4 has 4 medium-severity CVEs (XSS); unfixed well past patched versions.
  • Free-webmail dev email (numbered alias), no developer name — unaccountable publisher despite verified/featured badges.

Evidence

  • search_provider_override_is_default manifest chrome_settings_overrides.search_provider.is_default=true routes all search to default-search.site.
  • ad_infra_host_permission manifest host_permissions includes ext-ads-mvp.captain-products.workers.dev — 'ads-mvp' signals monetization infra.
  • generic_google_privacy_policy store Privacy policy URL is myaccount.google.com/privacypolicy — not scoped to this extension; admits 3rd-party sharing.
  • jquery_cve_bundle crx jquery@2.1.4 bundled with 4 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251).
  • free_webmail_numbered_alias_dev store Developer email jeff38399green@gmail.com is a numbered free-webmail alias; no developer name provided.
  • ad_ninja_skipply_external_js_hosts crx js_external_hosts includes ad-ninja.net and skipply.net — known ad/tracking domains.
  • verified_and_featured_but_numbered_alias store Verified publisher and featured badges coexist with numbered free-webmail email and absent developer name.
  • dom_xss_sink_in_vulnerable_jquery crx innerHTML DOM-XSS sink in jquery@2.1.4 which also carries 4 unpatched medium CVEs — compounded risk.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.1.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.1.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.1.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.1.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • unlimitedStorage low Allows unlimited local storage; low standalone risk.
  • storage low Basic key-value storage, standard for extensions.
  • declarativeNetRequest medium Can intercept/redirect network requests; medium risk without <all_urls>.
  • host_permission: https://default-search.site/ medium Grants access to the custom search endpoint operated by developer.
  • host_permission: https://ext-ads-mvp.captain-products.workers.dev/* high 'ads-mvp' in hostname strongly suggests ad-serving infra; not typical for a search changer.
  • chrome_settings_overrides.search_provider (is_default: true) high Replaces the default search engine with developer-controlled endpoint; high monetization/data risk.

Pillar Scores

Permissions6.50
Reputation6.50
Network3.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality3.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 04:35
Listing SHA 5f52b8b40592…
Force block — not fired
Score recovered no
Elapsed