Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

View Menu with Prices

ijbmkpeacbkgpfkomjbionjgdhbmlpfp
Risk Score
4.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 10,000
Rating
Last updated 2026-01-29 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@viewmenuprices.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search engine override routes all user searches to developer-controlled domain (viewmenuprices.com).
  • Uninstall URL hijack confirmed — tracks user uninstall events via third-party redirect.
  • Install URL hijack opens developer site on install — monetization/tracking pattern.
  • Privacy policy admits third-party data sharing but lacks retention disclosure.
  • No ratings, unverified developer, narrow-purpose domain controlling search traffic.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets is_default=true; all searches routed to viewmenuprices.com/auto-suggest/search.php
  • uninstall_url_hijack crx uninstall_url_hijack=true; target null but hijack flag set — tracks uninstall lifecycle.
  • install_url_hijack crx install_url_hijack=true; target https://viewmenuprices.com/extension-success/ — monetization/redirect pattern.
  • privacy_policy_third_party_sharing api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false, rating=0 with 0 reviews.
  • maintenance_stale store months_since_update=7; falls in 3-6 month band (+1.5).
  • webstore_install_count store 10,000 installs with search-override monetization shape raises blast-radius concern.
  • csp_absent_mv3 manifest content_security_policy=null; MV3 provides strict default so no network penalty applied.

Permissions Breakdown

  • chrome_settings_overrides.search_provider (is_default=true) medium Overrides default search engine to developer-controlled endpoint; intercepts all user searches.

Pillar Scores

Permissions4.00
Reputation5.00
Network0.00
Webstore8.50
Maintenance3.50
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:04
Listing SHA 187771f95aaf…
Force block — not fired
Score recovered no
Elapsed