Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SearchFort

eojfoigempgjbpppohfaapklfllbcidk
Risk Score
6.22
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Other
Installs
Rating
Last updated 2023-08-09 (36 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@fashionnewtab.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search hijack routes all queries to monetized feed.search-fort.com (publisherid=70662) without user awareness.
  • Privacy policy URL is unreachable (fetch error); developer domain fashionnewtab.com does not resolve — no accountability.
  • Extension is 36 months stale with no updates; abandoned or orphaned extension is acquisition/compromise risk.
  • Broad host_permissions (*://*/*) grant full page access despite a trivially simple stated function.
  • Developer name absent and developer domain dead; verified-publisher badge provides no meaningful assurance here.

Evidence

  • search_provider_override manifest is_default=true; search_url=feed.search-fort.com with publisherid/barcodeid monetization params.
  • broad_host_permissions manifest host_permissions includes *://*/* giving read/write access to all sites.
  • privacy_policy_unreachable api fetched=false, reason=fetch_error:ConnectionError; fashionnewtab.com does not resolve.
  • developer_domain_dead api threat_intel.developer_domain_info.resolves=false; domain fashionnewtab.com offline.
  • stale_extension store Last updated August 2023; months_since_update=36. No changelog visible.
  • no_developer_name store developer_name is empty string; no identifiable publisher beyond email.
  • mismatch_email_domain_vs_extension store Developer email @fashionnewtab.com but extension is SearchFort; domain mismatch suggests repurposed asset.
  • verified_publisher_cap_triggered api v3.5 invariant 0c: verified-publisher discount capped at -1.0 (domain not resolving + 36mo stale).

Permissions Breakdown

  • tabs medium Can read tab URLs/titles; medium risk on its own but paired with broad host access.
  • *://search-fort.com/ medium Grants full access to search-fort.com, the monetized search backend.
  • *://.search-fort.com/ medium Extends access to all subdomains of search-fort.com including feed subdomain.
  • *://*/* high Effectively <all_urls>: read/write access to all HTTP/HTTPS pages.
  • chrome_settings_overrides.search_provider high Forces default search engine to monetized feed.search-fort.com with publisherid parameter.

Pillar Scores

Permissions6.00
Reputation6.50
Network2.00
Webstore4.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:26
Listing SHA 18ae715a3d14…
Force block — not fired
Score recovered no
Elapsed