Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

RealSearch - Human Answers Only (No AI Spam)

jodmdafccdbmmonjcmckddlaplcigcjl
Risk Score
5.19
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 24
Rating 5.0
Last updated 2026-02-09 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer bigdeveloper44@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Free-webmail dev (bigdeveloper44@gmail.com) + no developer name + no business domain = high anonymity risk.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits broad data collection and 3rd-party sharing.
  • External JS host 'chromecrxstore.com' is unrecognized/suspicious; HK geo-diversity adds concern.
  • Brand impersonation: 'reddit' mentioned in description; developer not confirmed owner.
  • install_url_hijack flagged true; low install count (24) with multi-search-engine host access across 9 engines.

Evidence

  • free_webmail_dev_no_name store Developer email bigdeveloper44@gmail.com; developer_name empty; no business domain.
  • generic_google_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • suspicious_external_js_host crx js_external_hosts includes chromecrxstore.com — unrecognized domain, hosted in HK.
  • brand_impersonation store brand_mention.is_impersonation=true for 'reddit'; developer not confirmed owner.
  • install_url_hijack crx install_url_hijack=true; extension opens external URL on install.
  • multi_search_engine_contact manifest search_engine_count=9; host_permissions span 9 distinct search engines including Yandex and Baidu.
  • verified_publisher_featured_but_gmail store verified_publisher=true and is_featured_by_google=true but dev is anonymous free-webmail; reputation floor applies.
  • no_csp crx content_security_policy=null on MV3; csp_present=false.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; minimal privilege.
  • *://www.google.com/* medium Content-script access to Google search pages; matches stated function.
  • *://www.bing.com/* medium Content-script access to Bing; matches stated function.
  • *://*.duckduckgo.com/* medium Content-script access to DuckDuckGo; matches stated function.
  • *://*.yahoo.com/* medium Content-script access to Yahoo search; matches stated function.
  • *://*.yahoo.co.jp/* medium Content-script access to Yahoo Japan; matches stated function.
  • *://*.yahoo.co.in/* medium Content-script access to Yahoo India; matches stated function.
  • *://search.brave.com/* medium Content-script access to Brave search; matches stated function.
  • *://www.ecosia.org/* medium Content-script access to Ecosia; matches stated function.
  • *://www.baidu.com/* medium Content-script access to Baidu; matches stated function.
  • *://*.yandex.com/* medium Content-script on Yandex; Russian search engine, elevated geo-risk.
  • *://*.yandex.ru/* medium Content-script on Yandex.ru; Russian TLD, elevated geo-risk.
  • https://suggestqueries.google.com/* low Read-only Google autocomplete API; low risk.

Pillar Scores

Permissions3.00
Reputation7.50
Network2.00
Webstore6.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 15:49
Listing SHA d2f1c5075f04…
Force block — not fired
Score recovered no
Elapsed