Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Print Easily

ebgcanfjipfcdnjgpbagblmgebkpbhoo
Risk Score
6.55
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 30,000
Rating 1.0
Last updated 2025-08-12 (12 months ago)
Manifest version MV3
CSP present ❌ no
Developer walstabkai@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search-provider override (is_default=true) silently hijacks user's default search engine to quickprintapp.net.
  • Uninstall and install URL hijacks both present — classic traffic-monetization shell behavior.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (score +10).
  • Developer uses free-webmail Gmail address with no verified business identity.
  • Rating of 1.0 and cookies permission alongside search override creates high-impact credential/session risk.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets is_default=true, routing all searches to quickprintapp.net — monetization pattern.
  • uninstall_url_hijack crx uninstall_url_hijack=true; classic low-effort traffic-monetization fingerprint.
  • install_url_hijack crx install_url_hijack=true; opens 3rd-party URL on install — Webstore +2.0.
  • privacy_policy_inadequate api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy score.
  • free_webmail_developer store Developer email walstabkai@gmail.com — free webmail, no verified business; Reputation +1.5.
  • low_rating store Rating=1.0; users strongly dissatisfied, consistent with search-hijack complaint pattern.
  • cookies_permission_with_search_override manifest cookies + search_provider override is a credential-harvesting risk surface even without broad host_permissions.
  • maintenance_stale store months_since_update=12; falls in 6-12mo band → Maintenance +3.5.

Permissions Breakdown

  • storage low Local key-value store; minimal risk on its own.
  • cookies high Grants read/write access to cookies; paired with search-provider override this enables session hijack.
  • chrome_settings_overrides.search_provider (is_default=true) high Silently replaces the default search engine with quickprintapp.net; classic monetization override.

Pillar Scores

Permissions7.00
Reputation7.50
Network2.00
Webstore9.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:57
Listing SHA 801fd7e4cc25…
Force block — not fired
Score recovered no
Elapsed