Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Search'n Give

cooagkhjpjaoljncieegiefgphelgjhm
Risk Score
5.04
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 17
Rating 5.0
Last updated 2025-10-06 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@searchngive.org
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack + install URL hijack both flagged: onboarding/offboarding traffic redirected to 3rd party.
  • Search provider override sets itself as default engine (is_default:true) with only 17 installs — tail monetization risk.
  • Privacy policy admits data collection + third-party sharing but is NOT scoped to this extension — highest privacy score.
  • No developer name listed; verified publisher badge is sole accountability signal.
  • External JS host includes react.dev (CDN), introducing remote-code-loading risk surface.

Evidence

  • uninstall_url_hijack + install_url_hijack both true crx Both onInstalled and uninstall URL hooks set; standard monetization-shell fingerprint even with null targets.
  • chrome_settings_overrides search_provider is_default:true manifest Extension forcibly replaces default search engine with search.searchngive.org; core revenue mechanism.
  • privacy_policy scope_extension:false, data_collection:true, third_party_sharing:true api Policy admits collection+sharing but never scopes to this extension; triggers v3.5-D +10.0 privacy rule.
  • js_external_hosts includes react.dev crx External CDN host; if loaded at runtime could introduce remote code; no CSP to constrain it.
  • developer_name empty store No 'Offered by' name; verified_publisher is only accountability anchor.
  • install_count:17 store Extremely low install count; blast radius small but tail-attack-surface concern noted.
  • csp_present:false, manifest_version:3 manifest MV3 has strict default for service worker but no explicit CSP; no v2 +2.0 penalty applies.
  • verified_publisher:true, domain resolves, looks_throwaway:false api Publisher verified; domain live; mitigates reputation partially but privacy/hijack signals override.

Permissions Breakdown

  • storage low Persists local settings; no cross-origin data exposure.
  • host_permission:*://search.yahoo.com/* medium Allows content-script injection on Yahoo search; read/modify search results.
  • host_permission:https://www.searchngive.org/* low Dev-controlled domain; expected for settings/charity tracking.
  • chrome_settings_overrides.search_provider (is_default:true) medium Silently sets default search engine; core monetization mechanism.

Pillar Scores

Permissions3.50
Reputation5.00
Network2.00
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:33
Listing SHA edeb1490a1b3…
Force block — not fired
Score recovered no
Elapsed