Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Change Default Search

engdbbbcegcppebanfnafhnnojiipmij
Risk Score
5.69
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 194
Rating 3.0
Last updated 2025-07-17 (14 months ago)
Manifest version MV3
CSP present ✅ yes
Developer mihnevitch.ser@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search engine override routes all user queries through change-search.site, an unverifiable operator-controlled domain.
  • Privacy policy URL times out (fetch error); effective privacy posture is unknown — scored as no policy (+10.0).
  • Developer is gmail.com free-webmail with no developer name; confirmed Google brand impersonation (+2.0 reputation).
  • JS external hosts include 6 search engines plus change-search.site; geo-diversity spans RU/HK/CA/US (4 countries, +1.5 network).
  • Extension contacts 6 search engines — multi-search-engine NewTab anomaly heuristic partially applicable; monetization aggregator risk.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets is_default=true pointing to change-search.site/search — all queries redirected to operator domain.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (ReadTimeout); policy cannot be evaluated — treated as absent.
  • brand_impersonation store brand_mention.is_impersonation=true for 'google'; developer_domain=gmail.com, confirmed_owner=false.
  • free_webmail_no_dev_name store developer_email=mihnevitch.ser@gmail.com; developer_name empty; no verified business identity.
  • six_search_engines_contacted crx threat_intel.search_engine_count=6 (baidu, bing, duckduckgo, google, yahoo, yandex) plus change-search.site.
  • geo_diversity_4_countries api JS hosts span CA, HK, RU, US — 4 countries, triggering +1.5 network penalty.
  • maintenance_stale store months_since_update=14; falls in 12-24mo band (+6.0 maintenance).
  • verified_publisher_cap store verified_publisher=true but months_since_update>18 triggers v3.5 0c cap; discount capped at -1.0.

Permissions Breakdown

  • storage low Stores local config; low risk on its own.
  • declarativeNetRequest medium Can modify/block network requests; medium risk without broad host access.
  • chrome_settings_overrides.search_provider (is_default=true) high Overrides the default search engine to change-search.site — core monetization surface.
  • host_permissions: https://change-search.site/* medium Scoped to dev-controlled domain only; limits cross-site reach but routes searches through operator.

Pillar Scores

Permissions5.00
Reputation6.50
Network1.50
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 04:37
Listing SHA 1d5f109c7358…
Force block — not fired
Score recovered no
Elapsed