Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Easy How To

dfdkfkighakfgihcffnpboebfifbeddl
Risk Score
6.01
Risk Level: High
Recommendation: 🚫 BLOCK
Category NewTab
Installs 10,000
Rating 4.0
Last updated 2024-08-21 (24 months ago)
Manifest version MV3
CSP present ✅ yes
Developer EasyHowTo1982@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection + third-party sharing without scoping to this extension (D rule: +10.0 privacy).
  • Uninstall URL hijack and install URL hijack both flagged — classic traffic-monetization shell pattern (+3.0+2.0 webstore).
  • NewTab override with Bing search engine contact — ad-monetization surface (+2.0 webstore).
  • Gmail-only developer identity (EasyHowTo1982@gmail.com), no verified publisher, no business identity (+2.5 reputation floor).
  • Extension stale at 24 months with newtab override — zombie monetization risk (+6.0 maintenance).

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() present — traffic-monetization shell indicator (+3.0 webstore).
  • install_url_hijack crx onInstalled opens 3rd-party URL — install hijack pattern (+2.0 webstore).
  • privacy_policy_generic_collecting api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
  • newtab_override manifest chrome_url_overrides.newtab set; contacts bing.com for search — monetization shape (+2.0 webstore).
  • free_webmail_dev store Developer email EasyHowTo1982@gmail.com — numbered alias on free webmail, no verified publisher.
  • stale_extension store 24 months since last update with newtab override and 10K installs (+6.0 maintenance, zombie booster +1.0 at threshold).
  • dom_xss_sink crx innerHTML from variable in chunk JS; CSP present but no CVEs — +0.5 code quality (dom_sink alone, csp_present=true).
  • csp_connect_src_broad crx connect-src includes bing.com, geoip-js.com, openweathermap.org — 3+ distinct registrable domains (+1.5 network).

Permissions Breakdown

  • search medium Allows reading/modifying search provider; paired with newtab override raises monetization concern.
  • storage low Standard local key-value storage; limited standalone risk.
  • chrome_url_overrides.newtab medium Replaces new-tab page; high-frequency surface for monetization injection.

Pillar Scores

Permissions3.50
Reputation7.50
Network3.50
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:59
Listing SHA 77f858cd9421…
Force block — not fired
Score recovered no
Elapsed