Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Easy Search

eoonjagfcinffmfjlaghfppbgimlkbbk
Risk Score
4.05
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs
Rating
Last updated 2026-07-08 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer klichkox@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search-provider override silently routes all user queries to dev-controlled easy-search.pro domain.
  • Uninstall URL hijack detected — extension registers an uninstall callback to a third-party URL.
  • Free webmail developer (klichkox@gmail.com), no developer name, no verified publisher status.
  • Privacy policy fetched but scope_extension==false and third_party_sharing==true — not scoped to this extension.
  • No rating/install data available; extension has zero accountability signals.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets easy-search.pro as default search engine (is_default=true), hijacking all queries.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension registers uninstall URL, typical monetization/tracking shell pattern.
  • free_webmail_dev_no_name store Developer email klichkox@gmail.com, no developer_name set, no verified publisher badge.
  • privacy_policy_unscoped_third_party_sharing api Policy fetched; scope_extension=false, third_party_sharing=true — admits sharing without scoping to extension.
  • search_provider_medium_permission manifest Search override scored as MEDIUM (+1.0) per rubric; combined with no developer identity raises risk.
  • no_install_count_no_rating store install_count and rating_count both missing; no popularity or community trust signals available.
  • webstore_search_override_signal store +2.0 Webstore for search-provider override; +3.0 for uninstall URL hijack monetization pattern.
  • cve_clean_code_clean crx cve_findings_raw empty, code_findings_raw empty, obfuscation_score=0.0 — no code-level risk detected.

Permissions Breakdown

  • storage low Stores local extension settings; low impact alone.
  • chrome_settings_overrides.search_provider (is_default=true) medium Overrides default search engine to easy-search.pro, routing all queries through dev-controlled domain.
  • host_permissions: *://easy-search.pro/* medium Scoped to own domain only; needed for search function but still grants full access to that domain.

Pillar Scores

Permissions4.00
Reputation7.50
Network0.00
Webstore7.00
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:25
Listing SHA 1213c780c27f…
Force block — not fired
Score recovered no
Elapsed