Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

My Focal Find

eeejfmalgedffijdepcdmgemfnadjefe
Risk Score
6.88
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 30,000
Rating 1.0
Last updated 2024-05-23 (27 months ago)
Manifest version MV3
CSP present ❌ no
Developer reedd6868@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Default search engine override sends all omnibox queries to myfocalfind.com — a monetization-oriented search hijacker pattern.
  • Developer is free-webmail (gmail) with no developer name, rated 1-star; strong low-trust signal.
  • Uninstall URL hijack present — extension registers a 3rd-party uninstall redirect.
  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — generic boilerplate.
  • 27 months since last update; extension is effectively abandoned with 30K active users still exposed.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets myfocalfind.com as default search with is_default=true; all omnibox queries routed to it.
  • uninstall_url_hijack store uninstall_url_hijack=true; extension registers an uninstall URL redirect, a known monetization/tracking pattern.
  • developer_identity_weak store Developer email reedd6868@gmail.com (numbered alias + free webmail), no developer name, no verified business domain.
  • rating_1_star store Rating is 1.0 — lowest possible score, strongly indicating user dissatisfaction or search-hijack complaints.
  • privacy_policy_inadequate api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true — admits broad sharing, not scoped to extension.
  • stale_extension store Last updated May 2024, 27 months ago; falls in 24-36mo maintenance band (+8.5).
  • verified_publisher_featured store Marked verified_publisher and is_featured_by_google, but v2 cap applies: search override is HIGH capability, discount capped.
  • webstore_search_override_monetization manifest Search provider override (+2.0) stacked with uninstall hijack (+3.0) and numbered-alias email (+3.0) in webstore pillar.

Permissions Breakdown

  • storage low Standard local storage for extension settings; low risk.
  • declarativeNetRequest medium Can intercept/redirect network requests; medium risk but no host wildcard.
  • chrome_settings_overrides.search_provider (is_default=true) high Overrides default search engine to myfocalfind.com; hijacks all omnibox searches.
  • host_permissions: *://myfocalfind.com/* low Scoped to own domain only; narrow host access.

Pillar Scores

Permissions6.50
Reputation7.50
Network2.00
Webstore7.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:07
Listing SHA 449c6573140a…
Force block — not fired
Score recovered no
Elapsed