Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

OmniSearch

djgflnccplcmifemnpgnkkdblihncpmm
Risk Score
6.47
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 80,000
Rating
Last updated 2022-05-24 (51 months ago)
Manifest version MV3
CSP present ❌ no
Developer omnisearch@avq.co
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search-provider override routes all queries to defaultsearch.co (adaware ecosystem) — classic search hijack.
  • Uninstall URL hijack: extension sets custom uninstall URL to third-party destination.
  • Privacy policy (adaware.com) not scoped to this extension, admits data collection and third-party sharing.
  • Extension is 51 months stale (MV3 but abandoned since May 2022) with 80K active installs still exposed.
  • JS external hosts include flow.lavasoft.com and mynewtab.co — Lavasoft/adaware monetization infrastructure.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets default search to defaultsearch.co/?sp=11&q={searchTerms}, routing all queries through adaware monetization.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension registers a third-party uninstall URL, tracking removal events.
  • privacy_policy_inadequate api Policy fetched from adaware.com: scope_extension=false, data_collection=true, third_party_sharing=true, retention=false.
  • stale_extension store Last updated May 2022 (51 months ago); 80K installs still active on abandoned codebase.
  • external_hosts_adaware crx JS external hosts: flow.lavasoft.com (Lavasoft/adaware telemetry) and mynewtab.co.
  • shell_pattern_description store description_promise.is_shell_pattern=true; vague promise ('fast access to search results') masks search hijack function.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; developer identity is 'omnisearch' with avq.co domain.
  • triple_stale_fingerprint store v2 calibration: >24mo stale + MV3 + no CVEs but Lavasoft-associated infra; +2.0 webstore triple-stale applied.

Permissions Breakdown

  • storage low Stores extension settings locally; minimal risk.
  • chrome_settings_overrides.search_provider (is_default=true) medium Forces default search engine to defaultsearch.co; classic search-hijack vector.
  • host_permissions: https://flow.lavasoft.com/* medium Lavasoft adware-associated domain; outbound data channel risk.
  • host_permissions: https://defaultsearch.co/* medium Monetized search provider; redirects user queries.
  • host_permissions: https://in.adaware.com/* medium Adaware tracking/telemetry endpoint; data exfil channel.

Pillar Scores

Permissions4.00
Reputation5.50
Network2.00
Webstore7.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:31
Listing SHA db12deeec2fd…
Force block — not fired
Score recovered no
Elapsed