Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Health Search Pro

fmmickkobhbfclcaejbkbkfjejpddfjg
Risk Score
7.10
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 1,000
Rating 1.0
Last updated 2025-07-10 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer healthsearchpro@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search engine hijacked to ofsrchrdr.com — a third-party ad/monetization redirector, not the developer's own domain.
  • Uninstall URL hijack detected; extension redirects users upon removal, classic search-hijacker fingerprint.
  • Privacy policy fetched but not scoped to this extension; admits data collection and third-party sharing — worst-case disclosure.
  • Free-webmail developer (gmail), no developer name, no verified publisher — anonymous high-capability actor.
  • webRequest permission combined with search-provider override enables full query interception and monetization of all user searches.

Evidence

  • search_provider_override manifest is_default=true, search_url routes to ofsrchrdr.com with tracking param dgd=RD1005463; third-party monetization redirector.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension registers an uninstall redirect — common search-hijacker pattern.
  • privacy_policy_generic api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — admits collection without extension scope.
  • developer_identity store developer_email=healthsearchpro@gmail.com, developer_name empty, verified_publisher=false, is_featured=false.
  • webRequest_high_permission manifest webRequest declared alongside search-provider override; can intercept all queries routed through hijacked engine.
  • rating_signal store Rating=1.0 — worst possible rating; indicates user-reported harm or dissatisfaction.
  • maintenance_stale store months_since_update=14; falls in 12-24 month band (+6.0 maintenance score).
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; low-install extension with high-tier permissions.

Permissions Breakdown

  • storage low Stores extension preferences; low risk alone.
  • webRequest high Can observe and intercept all network requests; major surveillance capability.
  • activeTab medium Access to currently active tab content on user interaction.
  • https://*.healthsearchpro.com/* medium Scoped host access to dev domain; moderate risk, enables data exfil to controlled server.
  • https://*.ofsrchrdr.com/* high Third-party search redirector domain used as default search — not dev-controlled identity.
  • chrome_settings_overrides.search_provider (is_default:true) high Forces default search engine to ofsrchrdr.com, a monetization redirector; high-impact override.

Pillar Scores

Permissions7.00
Reputation8.50
Network4.00
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 06:15
Listing SHA 19020a10a9c0…
Force block — not fired
Score recovered no
Elapsed