Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Beamo Search

ghfpmfejffpjebfokeikjimnommbpaon
Risk Score
3.55
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category NewTab
Installs 4
Rating
Last updated 2026-07-24 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer beamo@beamosupport.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • NewTab + default search engine override routes all user queries to unknown beamosearch.com provider.
  • No developer name disclosed; identity accountability gap for an extension controlling search behavior.
  • search_redirect_probe: is_direct_provider=false — query path through beamosearch.com is not direct search.
  • 12 external JS hosts contacted (weather, maps, dictionary APIs) expand network attack surface.
  • Very low install count (4) with unknown developer raises tail-attack-surface concern.

Evidence

  • NewTab + search_provider override manifest chrome_url_overrides.newtab and chrome_settings_overrides.search_provider both set to beamosearch.com; all queries routed there.
  • search_redirect_probe not direct provider api is_direct_provider=false; final_host=beamosearch.com but redirect_host=null. Query path unclear.
  • No developer name store developer_name is empty string; no identity accountability for search/newtab override.
  • 12 external JS hosts crx Contacts open-meteo, mapbox, datamuse, openstreetmap, frankfurter, dictionaryapi, er-api, wiktionary, weather.gov etc.
  • Privacy policy adequate api fetched=true, scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
  • No bad hosts or monetization hits api threat_intel bad_host_hits=[], monetization_hits=[], affiliate_hits=[] — no known malicious infrastructure.
  • Clean code scan crx code_findings_raw=[], obfuscation_score=0.0, js_libraries_detected=[], cve_findings_raw=[].
  • Operator singleton, no siblings api operator_cluster.sibling_count=0; no known related extensions under same fingerprint.

Permissions Breakdown

  • contextMenus low Used to add right-click search option; low standalone risk.
  • scripting medium Can inject scripts into pages; scoped to beamosearch.com only per host_permissions.
  • tabs medium Can read tab URLs and titles; moderate risk for browsing data exposure.
  • storage low Stores preferences locally; low risk.
  • chrome_url_overrides.newtab medium Replaces new-tab page; monetization vector and visibility into user habits.
  • chrome_settings_overrides.search_provider medium Sets default search engine to beamosearch.com; all queries routed through unknown provider.
  • host_permissions: https://beamosearch.com/* low Narrow host permission scoped to own domain only.

Pillar Scores

Permissions5.50
Reputation6.00
Network2.50
Webstore5.50
Maintenance0.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:23
Listing SHA e893bc1d4780…
Force block — not fired
Score recovered no
Elapsed