Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Easy Login

cpmjnpalighpdecgankobogpcmbceaig
Risk Score
6.44
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 10,000
Rating 2.5
Last updated 2025-08-21 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@mytrueapps.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search engine hijacked to loginonlineapp.com — routes all queries through operator-controlled endpoint.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (D clause: +10.0).
  • Uninstall URL hijack and install URL hijack both active — aggressive lifecycle monetization.
  • cookies permission against operator's own search domain enables session/credential capture.
  • Rating of 2.5 signals user dissatisfaction consistent with unwanted search override behaviour.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets is_default=true search engine to loginonlineapp.com — classic search hijack.
  • uninstall_url_hijack manifest uninstall_url_hijack=true; extension intercepts uninstall lifecycle for 3rd-party redirect.
  • install_url_hijack manifest install_url_hijack=true; opens external URL on install — monetization or affiliate signal.
  • privacy_policy_d_clause crx Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • cookies_permission manifest cookies declared alongside host access to loginonlineapp.com; can capture auth cookies.
  • low_rating store Rating 2.5 consistent with user-reported unwanted search/browser changes.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
  • webstore_search_override_monetization store search_provider override + install/uninstall hijacks = textbook traffic-monetization cluster.

Permissions Breakdown

  • storage low Standard local data persistence, low risk in isolation.
  • cookies high Can read/write cookies; scoped to loginonlineapp.com but still high-sensitivity API.
  • host_permission: *://*.loginonlineapp.com/* medium Narrow host scope to own domain, but combined with cookies enables credential exfil.
  • chrome_settings_overrides.search_provider (is_default=true) high Hijacks default search engine to loginonlineapp.com — classic monetization/search override.

Pillar Scores

Permissions7.00
Reputation6.00
Network2.00
Webstore9.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:07
Listing SHA c02b412ec6d4…
Force block — not fired
Score recovered no
Elapsed