Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Flex Search Engine

cmahifelbbglhkphmfhacamaigkcknop
Risk Score
5.14
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 9,000
Rating
Last updated 2025-06-16 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer nicks@worthathousandwords.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search-provider override routes all user queries to flexsearchengine.com with no transparency about data handling.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — worst-case disclosure.
  • Developer name absent; 15-month stale extension with no rating signals low accountability.
  • declarativeNetRequest can redirect/block network requests with no CSP present (MV3 default CSP applies but no explicit policy).
  • Maintenance gap (12-24 months) raises supply-chain risk if domain ownership changes.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets is_default:true, routing all queries to flexsearchengine.com/ext/search.
  • privacy_policy_unscoped_with_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → D(v3.5) +10.0.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity visible.
  • stale_extension store months_since_update=15; falls in 12-24mo band (+6.0 maintenance).
  • declarativeNetRequest_no_csp manifest declarativeNetRequest declared; csp_present=false (MV3 default applies, no explicit CSP).
  • no_rating store Rating=0 with 9,000 installs; no user trust signal.
  • search_engine_override_webstore store +2.0 webstore for search-provider override pattern.
  • cve_findings_empty crx No CVEs detected in bundled JS libraries; CVE pillar=0.

Permissions Breakdown

  • storage low Stores local preferences; no cross-origin access.
  • declarativeNetRequest medium Can intercept/block/redirect network requests via static rules.
  • chrome_settings_overrides.search_provider (is_default:true) medium Silently replaces default search engine; all queries routed to flexsearchengine.com.
  • host_permissions: https://flexsearchengine.com/* low Scoped to single developer-owned domain only.

Pillar Scores

Permissions3.50
Reputation6.00
Network2.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 05:34
Listing SHA fe9a89198438…
Force block — not fired
Score recovered no
Elapsed