Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Fresh Fruit Search

jeookppofphgjnhjkifeejcmjbpiogka
Risk Score
6.10
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 10,000
Rating 1.0
Last updated 2024-05-28 (27 months ago)
Manifest version MV3
CSP present ❌ no
Developer wallacenathan330@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search engine override sends all user queries to freshfruittab.com with no independent audit.
  • Developer is gmail-only with no verified business identity; verified_publisher badge is the only trust signal.
  • Rating of 1.0 is a severe negative signal suggesting users are unhappy or experiencing unwanted behavior.
  • Extension is 27 months stale (zombie risk) — no updates since May 2024 on an active search override.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension.

Evidence

  • search_provider_override_default manifest chrome_settings_overrides sets freshfruittab.com as default search engine (is_default=true); all user queries routed there.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension registers an uninstall URL, a monetization/tracking indicator.
  • low_rating store Rating is 1.0; strong negative user satisfaction signal consistent with unwanted search hijack behavior.
  • developer_identity_weak store Developer email wallacenathan330@gmail.com (free webmail), no developer_name set, no verified business domain.
  • maintenance_stale store Last updated May 2024; 27 months since update places in 24-36mo band (+8.5 maintenance score).
  • privacy_policy_insufficient api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — admits collection without scoping to extension.
  • verified_publisher_present store verified_publisher=true; provides -3.0 reputation discount but capped at -1.0 due to monetization concern (stale >18mo).
  • webstore_search_override_monetization manifest Search provider override (+2.0 webstore) combined with uninstall hijack (+3.0 webstore) = primary monetization shell signals.

Permissions Breakdown

  • storage low Stores local settings; low standalone risk.
  • declarativeNetRequest medium Can modify/block network requests; medium risk without broad host access.
  • chrome_settings_overrides.search_provider (is_default=true) high Silently overrides default search engine; core monetization/exfil vector for all queries.
  • host_permissions: *://freshfruittab.com/* low Scoped to own domain only; limited reach.

Pillar Scores

Permissions4.00
Reputation7.50
Network0.00
Webstore7.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:05
Listing SHA e7a2eef0a4e2…
Force block — not fired
Score recovered no
Elapsed