Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Safe Search

fmhohpnoklemblfiefcmaimondboemkj
Risk Score
5.39
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 5
Rating
Last updated 2026-03-14 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer service@explorads.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search engine override redirects all queries to blpsearch.com with tracking parameters (source, pc, form).
  • Uninstall URL hijack active; extension controls post-removal navigation.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
  • cookies permission + host access to expldata.com enables cross-site cookie reading and data exfiltration.
  • Only 5 installs with high-tier permissions indicates tail-attack-surface risk (low scrutiny, high capability).

Evidence

  • search_provider_override manifest chrome_settings_overrides sets is_default=true, routing all searches to blpsearch.com with tracking params.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension sets a custom uninstall URL, controlling post-removal navigation.
  • privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — not scoped to this extension.
  • expldata_host_permission manifest Host permission for *.expldata.com/* is a second dev-controlled analytics domain with no described user-facing function.
  • no_developer_name store developer_name is empty string; reduces accountability.
  • install_perm_anomaly api Only 5 installs but has_high_tier_permission=true and small_install_high_perm=true.
  • verified_publisher store verified_publisher=true for explorads.com; resolves=true, looks_throwaway=false. Partial trust credit applied.
  • no_csp manifest csp_present=false on MV3; no custom CSP declared, relying only on MV3 defaults.

Permissions Breakdown

  • storage low Standard local data persistence; low standalone risk.
  • cookies high Can read/write cookies across scoped hosts; enables session hijack or tracking.
  • tabs medium Exposes tab URLs and metadata; combined with search override raises tracking risk.
  • activeTab low Transient access to current tab on user gesture; limited scope.
  • declarativeNetRequest medium Can redirect/block network requests; used here alongside search override.
  • scripting medium Programmatic script injection into pages; elevates capability when paired with host access.
  • host: https://*.blpsearch.com/* medium Developer-controlled search domain; required for feature but enables full cookie/DOM access.
  • host: https://*.expldata.com/* high Second developer domain (data/analytics); unexplained broad host access raises data-exfil concern.
  • host: https://*.yahoo.com/* medium Broad access to all Yahoo subdomains including search results and mail.
  • chrome_settings_overrides.search_provider (is_default) high Silently replaces default search engine; classic search-hijack monetization pattern.

Pillar Scores

Permissions7.50
Reputation4.50
Network2.50
Webstore7.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:23
Listing SHA a2b01f8082f1…
Force block — not fired
Score recovered no
Elapsed