Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Majestic Mountain Views

jgkjicglapnoiojomfhcgchmckpgfmag
Risk Score
6.56
Risk Level: High
Recommendation: 🚫 BLOCK FORCE-BLOCK
Category NewTab
Installs 20,000
Rating 5.0
Last updated 2026-07-11 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@syndic8.asia
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • FORCE BLOCK: management + new-tab/search override — extension can disable security tools AND has full traffic-routing capability.
  • management permission allows disabling/removing other installed extensions — high-impact capability.
  • Search provider override routes all user searches through landscape-extensions.com (policy: data collection + third-party sharing confirmed).
  • NewTab override + search override dual hijack maximizes user reach for monetization/tracking.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — generic policy on separate domain.

Evidence

  • management permission declared manifest management is a HIGH-risk permission enabling enumeration and removal of other extensions.
  • NewTab + search provider dual override manifest chrome_url_overrides.newtab and chrome_settings_overrides.search_provider both set; all searches routed to landscape-extensions.com.
  • Privacy policy: data collection + third-party sharing, not scoped to extension api scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
  • No developer name provided store developer_name is empty; identity accountability gap.
  • 11 external JS hosts including finance, sports, aviation APIs crx api.aviationstack.com, api.coingecko.com, api.twelvedata.com, www.thesportsdb.com, date.nager.at — broad unrelated data surface.
  • Verified publisher store verified_publisher=true; -3.0 reputation discount applied, but capability gate invoked for HIGH-impact permissions.
  • search_redirect_probe: intermediate redirect through search.yahoo.com api final_host=landscape-extensions.com but redirect_host=search.yahoo.com; is_direct_provider=true so +1.5 not triggered.
  • No CSP declared (MV3 default strict enforced) manifest csp_present=false; MV3 has strict default so no +2.0 MV2 penalty applies.

Permissions Breakdown

  • management high Can enumerate, disable, or uninstall other extensions — powerful lateral capability.
  • geolocation medium Physical location access; relevant to weather widget but still sensitive PII.
  • search medium Programmatic control of search engine settings; pairs with search_provider override.
  • chrome_url_overrides.newtab high Hijacks every new-tab page; high reach and monetization/tracking surface.
  • chrome_settings_overrides.search_provider high Forces custom search engine as default; routes all searches through landscape-extensions.com.
  • host_permissions: https://api.open-meteo.com/* low Scoped to a public weather API; limited blast radius.

Pillar Scores

Permissions7.50
Reputation4.50
Network2.50
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 16:21
Listing SHA bcc51807fbef…
Force block 🚫 fired
Score recovered no
Elapsed