Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MetaGer Search

gjfllojpkdnjaiaokblkmjlebiagbphd
Risk Score
3.73
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category PrivacyTool
Installs 815
Rating 3.0
Last updated 2026-08-28
Manifest version MV3
CSP present ❌ no
Developer support+webextension@metager.de
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (not scoped to this extension) yet admits data collection and third-party sharing — score +10.
  • Developer name field is empty; no 'Offered by' display name reduces accountability.
  • Search provider override sets MetaGer as default search engine without explicit user confirmation flow visible.
  • Small install base (815) combined with HIGH-tier permissions (webRequest, cookies, declarativeNetRequestWithHostAccess) raises tail-attack-surface concern.
  • No CSP declared (MV3 default applies, but no explicit policy) alongside webRequest/cookies on scoped hosts.

Evidence

  • privacy_policy_generic_google store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10 Privacy (v3.5 D).
  • verified_publisher store Extension has verified publisher badge; metager.de resolves, no monetization hits, no CVEs — full -3.0 discount applies.
  • developer_name_empty store developer_name is empty string; no 'Offered by' display name visible, adding +1.0 Reputation.
  • search_provider_override manifest chrome_settings_overrides sets MetaGer as default search provider; +1.0 Permissions per rubric (a).
  • install_perm_anomaly api 815 installs with HIGH-tier permissions (webRequest, cookies, declarativeNetRequest); small_install_high_perm=true → +1.5 Webstore.
  • no_cve_no_code_findings crx cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0 — CVE and Code Quality pillars score 0.
  • host_scope_narrow manifest host_permissions and content_scripts scoped exclusively to metager.org and metager.de; no broad host access.
  • threat_intel_clean api bad_host_hits=[], monetization_hits=[], affiliate_hits=[], looks_throwaway=false, geo_countries=[DE] only.

Permissions Breakdown

  • storage low Standard local state persistence; low risk.
  • cookies high Can read/write cookies; scoped to metager.org/de host_permissions only, limiting exposure.
  • webRequest high Observe network requests; scoped to metager hosts, plausible for search provider use.
  • declarativeNetRequestWithHostAccess high Can block/redirect requests; scoped to metager hosts reduces blast radius.
  • alarms low Schedule background tasks; minimal risk on its own.
  • host_permissions: https://metager.org/* medium Scoped to developer-owned domain; consistent with search provider function.
  • host_permissions: https://metager.de/* medium Scoped to developer-owned domain; consistent with search provider function.
  • chrome_settings_overrides.search_provider (is_default: true) medium Sets MetaGer as default search engine; declared function but overrides user setting.

Pillar Scores

Permissions4.50
Reputation4.00
Network2.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:22
Listing SHA 024142c4e1df…
Force block — not fired
Score recovered no
Elapsed