Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Safesearch Lab

ddhbcphmccakdjfddpnkhdnnnmjfgekh
Risk Score
4.09
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 10,000
Rating 4.7
Last updated 2026-07-14 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer kirdub2112@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search engine override routes all browser searches to safesearchlab.com — developer-controlled server with no known accountability.
  • Developer is a free-webmail Gmail user with no 'Offered by' name and no verifiable business identity.
  • Privacy policy is Google's own account policy — does not scope to this extension, admits data collection and third-party sharing.
  • Verified publisher badge present but invariant 0c does not cap discount here; however, free-webmail identity severely limits trust value of badge.
  • 10,000 installs amplify blast radius of any future malicious update to the safesearchlab.com search endpoint.

Evidence

  • search_provider_override manifest chrome_settings_overrides.search_provider sets is_default=true, routing all queries to https://safesearchlab.com/search/?q={searchTerms}
  • free_webmail_developer store Developer email kirdub2112@gmail.com is a free Gmail account; developer_name is empty; no verifiable business entity.
  • privacy_policy_generic store Privacy policy URL is Google's account policy, scope_extension=false, data_collection=true, third_party_sharing=true — not scoped to this extension.
  • verified_publisher store verified_publisher=true but paired with free-webmail identity; discount capped under free-webmail floor rules.
  • no_js_files crx js_file_count=0, code_findings_raw empty, obfuscation_score=0.0 — extension is manifest-only search override.
  • webstore_search_override store +2.0 Webstore for search-provider override per rubric; installs=10,000 adds +1.0.
  • no_bad_hosts api threat_intel bad_host_hits, monetization_hits, affiliate_hits all empty; no known-bad network signals.
  • cve_none crx cve_findings_raw empty; no bundled JS libraries detected; CVE pillar = 0.0.

Permissions Breakdown

  • chrome_settings_overrides.search_provider (is_default=true) medium Silently replaces browser default search engine with safesearchlab.com; all queries routed through developer's server.

Pillar Scores

Permissions3.00
Reputation7.50
Network0.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 04:36
Listing SHA 6e6b3c65520b…
Force block — not fired
Score recovered no
Elapsed