Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Template Search

cnkcgoiimpncbonlilkekbigfhchcbgb
Risk Score
6.49
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Other
Installs 50,000
Rating 2.3
Last updated 2025-02-01 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer templatesearchnow@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search engine hijacked to developer-controlled endpoint (templatesearch-svc.org); uninstall URL also hijacked.
  • Privacy policy admits data collection + third-party sharing but has no extension-specific scope — maximum privacy score.
  • Three moderate CVEs in bundled jquery@3.3.1 (below fixed_in 3.5.0); no CSP amplifies XSS exploitability.
  • Free-webmail developer (gmail) with no verified publisher badge and a 2.3 rating signals low-accountability operator.
  • Extension stale at 18 months with known-vulnerable jQuery; no code update to patch CVEs.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets default search to services.templatesearch-svc.org; is_default=true.
  • uninstall_url_hijack crx uninstall_url_hijack==true; extension registers uninstall URL redirect to 3rd-party endpoint.
  • privacy_policy_generic_admits_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule → +10.0.
  • jquery_cve_trio crx jquery@3.3.1 has 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
  • no_csp_amplifies_cve manifest csp_present=false; jquery@<3.5 + no CSP triggers v2e +2.0 Code Quality penalty.
  • free_webmail_developer store Developer email templatesearchnow@gmail.com; no verified publisher; no featured badge.
  • low_rating store Rating 2.3; extension has 50K installs but poor user satisfaction signal.
  • stale_18mo store Last updated Feb 2025; months_since_update=18; CVEs unpatched for full stale window.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • cookies high Allows reading/writing cookies across permitted origins; combined with search override = tracking risk.
  • storage low Local extension storage; low standalone risk.
  • tabs medium Can read tab URLs and titles; supports user surveillance when combined with other permissions.
  • search medium Allows overriding the browser search engine; monetization risk.
  • declarativeNetRequest medium Can redirect or block network requests; combined with search override elevates risk.
  • chrome_settings_overrides.search_provider high Sets default search engine to developer-controlled endpoint; classic search-hijack vector.
  • host_permissions: *://*.templatesearch-svc.org/* medium Scoped to developer domain but enables cookie and request access on all subdomain traffic.

Pillar Scores

Permissions7.00
Reputation7.50
Network2.00
Webstore7.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:13
Listing SHA b382c1e5d3bc…
Force block — not fired
Score recovered no
Elapsed