Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Pointcoin - Search & Earn

jdbelhlllpkdmeoopdhanocdfdcnaejd
Risk Score
6.27
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 34
Rating 1.0
Last updated 2026-08-05
Manifest version MV3
CSP present ❌ no
Developer extensions@bajaar.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search provider override routes ALL searches through extapi.pointcoin.app — complete query interception.
  • Uninstall + install URL hijacking: tracks install/uninstall lifecycle via 3rd-party redirects.
  • Privacy policy admits data collection and third-party sharing without scoping to this extension — D clause +10.0.
  • Content scripts injected on Google, Amazon checkout, ChatGPT, Claude, Copilot, Gemini, Grok — extremely broad sensitive-page coverage.
  • Google AdSense (pagead2.googlesyndication.com) in JS hosts + 3 search engines contacted = monetization shell pattern.

Evidence

  • search_provider_override manifest chrome_settings_overrides.search_provider is_default=true; routes searches to extapi.pointcoin.app/psearchx.
  • uninstall_and_install_url_hijack manifest Both uninstall_url_hijack and install_url_hijack are true — lifecycle event tracking.
  • monetization_host crx pagead2.googlesyndication.com in js_external_hosts; Google AdSense monetization confirmed.
  • privacy_policy_generic_with_sharing api scope_extension=false, data_collection=true, third_party_sharing=true — v3.5(D) hard +10.0.
  • multi_search_engine_contact crx search_engine_count=3 (bing, google, yahoo) in external hosts — ad-monetization aggregator pattern.
  • content_scripts_sensitive_pages manifest Scripts on Amazon checkout, ChatGPT, Claude, Gemini, Grok, Google Search, Perplexity — high-sensitivity injection.
  • trk_pubtailer_host crx trk.pubtailer.com in js_external_hosts — ad-tracking/publisher monetization network.
  • no_developer_name store developer_name is empty string; no verified publisher badge; rating=1.

Permissions Breakdown

  • storage low Local key-value storage; limited risk alone.
  • tabs medium Can read URLs and titles of all open tabs.
  • host: https://extapi.pointcoin.app/* medium Extension's own backend API; expected but tunnels search data.
  • host: https://api.bing.com/* medium Bing API access; search query interception risk.
  • content_scripts: search/AI/shopping/chat platforms high Scripts injected into Google, Bing, ChatGPT, Claude, Amazon checkout — broad sensitive-page access.
  • chrome_settings_overrides: search_provider (is_default=true) high Overrides default search engine to extension-controlled endpoint; all searches routed through extapi.pointcoin.app.

Pillar Scores

Permissions6.00
Reputation7.00
Network4.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:24
Listing SHA 8c869fd55b30…
Force block — not fired
Score recovered no
Elapsed