Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Easy PDF Viewer

jgdddeonphekfhicmnpffkfpboalmcjd
Risk Score
7.04
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 50,000
Rating
Last updated 2025-06-09 (14 months ago)
Manifest version MV3
CSP present ❌ no
Developer richardpdfman1983@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search-provider override set as default — routes all searches through easypdfviewer.net, a monetization shell pattern.
  • Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension (+10 privacy).
  • Developer is free-webmail gmail address (richardpdfman1983@gmail.com) with no verified business identity.
  • Both install and uninstall URL hijacks present — tracks user lifecycle for ad-tech pipelines.
  • 14-month stale update cycle with cookies permission and unscoped third-party-sharing policy.

Evidence

  • search_provider_override_default manifest chrome_settings_overrides sets is_default=true, routing all searches to easypdfviewer.net/admin/public/link.
  • uninstall_url_hijack store uninstall_url_hijack=true; extension registers an uninstall callback to a third-party URL.
  • install_url_hijack store install_url_hijack=true; extension opens third-party URL on install.
  • privacy_policy_generic_with_3rd_party_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — D rule triggers +10.
  • free_webmail_developer store Developer email richardpdfman1983@gmail.com; numbered-alias gmail, no verified business domain.
  • numbered_alias_email store Email matches numbered-alias pattern (richardpdfman1983) — Webstore +3.0 penalty applied.
  • cookies_with_search_override manifest cookies permission paired with default search_provider override enables cross-site session correlation.
  • stale_14mo store Last updated June 2025 but months_since_update=14; falls in 12-24mo band (+6.0 maintenance).

Permissions Breakdown

  • storage low Stores extension state locally; low standalone risk.
  • cookies high Can read/write cookies; combined with search_provider override enables session tracking.
  • chrome_settings_overrides.search_provider (is_default=true) high Silently replaces default search engine; classic monetization/data-harvesting vector.

Pillar Scores

Permissions7.00
Reputation7.50
Network0.00
Webstore10.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 11:33
Listing SHA 3470542ce085…
Force block — not fired
Score recovered no
Elapsed