Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Newz Finder

hfhfmkmokccaciopjahpkmfdbkjbhmfp
Risk Score
4.44
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 40,000
Rating 4.2
Last updated 2024-05-28 (28 months ago)
Manifest version MV3
CSP present ❌ no
Developer admin@newzfinder.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider hijacked to search.mybrowsingsafety.pro — a third-party ad-monetization endpoint, not the developer's domain.
  • Uninstall and install URL hijacks both active — classic browser-hijacker behavioral fingerprint.
  • Extension stale 28 months with no updates; verified-publisher discount capped to -1.0 due to months_since_update > 18.
  • Privacy policy discloses data collection and third-party sharing without retention period — inadequate for scope.
  • DOM-XSS sink (innerHTML) in popup.js with no CSP; amplifies attack surface if search provider serves malicious content.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets default search to search.mybrowsingsafety.pro — third-party monetization domain, not developer domain.
  • uninstall_url_hijack crx uninstall_url_hijack=true; install_url_hijack=true — both hijack patterns present, typical browser-hijacker cluster.
  • stale_extension store 28 months since last update (May 2024); verified-publisher discount capped at -1.0 per invariant 0c (>18mo stale).
  • no_developer_name store developer_name is empty string; reduces accountability signal.
  • privacy_policy_inadequate api Policy scoped, collects data, shares with third parties, but retention not disclosed — privacy pillar +1.0 for retention gap.
  • dom_xss_sink_no_csp crx innerHTML from user-controlled var in popup.js; csp_present=false triggers FIX B elevation to +2.0.
  • search_override_webstore_penalty manifest Search-provider override scored +2.0 in Webstore (monetization shape); stacked with install/uninstall hijack +3.0 each.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discounts applied but capped due to staleness >18mo.

Permissions Breakdown

  • storage low Stores local settings only; low standalone risk.
  • chrome_settings_overrides.search_provider medium Overrides default search engine to search.mybrowsingsafety.pro; monetization risk.

Pillar Scores

Permissions3.50
Reputation4.00
Network2.00
Webstore8.00
Maintenance6.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 05:32
Listing SHA b634bd6d3ab6…
Force block — not fired
Score recovered no
Elapsed