Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Better Search

epdmngmgidehpmhjamdjcaecpligmcfh
Risk Score
6.55
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 100,000
Rating 4.3
Last updated 2026-06-11 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer bettersearchus@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search-provider override routes ALL user queries to getbettersearch-api.com via free-webmail-only developer.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic policy).
  • Uninstall URL hijack detected — redirects users to third-party URL on removal.
  • Developer identity is a Gmail address with no verified business; no verified publisher badge.
  • cookies permission combined with search override enables full session + query history correlation.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets default search to search.getbettersearch-api.com, capturing all queries.
  • uninstall_url_hijack crx uninstall_url_hijack=true; routes users to third-party URL on extension removal.
  • privacy_policy_generic_with_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic, admits sharing.
  • free_webmail_developer store Developer email bettersearchus@gmail.com; no verified publisher, no business domain identity.
  • cookies_permission manifest cookies permission combined with search override enables cross-session query + cookie correlation.
  • js_external_hosts crx JS contacts api., search., uninstall. subdomains of getbettersearch-api.com — 3 distinct endpoints.
  • install_count_100k store 100,000 installs amplifies blast radius of search hijack and data collection.
  • no_csp manifest content_security_policy is null; MV3 strict default applies but no explicit CSP declared.

Permissions Breakdown

  • cookies high Can read/write cookies across allowed hosts; combined with search-provider override, enables session tracking.
  • storage low Local extension storage only; low standalone risk.
  • tabs medium Access to tab URLs/titles; combined with search override reveals full query history.
  • declarativeNetRequest medium Can modify/block network requests; supports search redirection infrastructure.
  • alarms low Scheduled callbacks; low direct risk but enables persistent background activity.
  • *://*.getbettersearch-api.com/* high Scoped host permission to dev-controlled domain; all search queries routed here.
  • chrome_settings_overrides.search_provider high Silently replaces default search engine; all user queries exfiltrated to getbettersearch-api.com.

Pillar Scores

Permissions7.50
Reputation7.50
Network4.50
Webstore9.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:14
Listing SHA ac16e25fbf16…
Force block — not fired
Score recovered no
Elapsed