Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Quick Search Tool

keadechokmcohlcampccppbjjeabghcd
Risk Score
7.07
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 100,000
Rating 5.0
Last updated 2024-04-02 (28 months ago)
Manifest version MV3
CSP present ❌ no
Developer tcirakovictech90@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Default search-engine override routes all address-bar queries through unvetted third-party domain with no clear privacy commitment.
  • Uninstall URL hijack confirmed — extension manipulates browser behavior on removal.
  • Install URL hijack confirmed — extension opens external URL on install without user consent.
  • Privacy policy is 271-char stub: fetched but no scope, data collection, or retention disclosure — effectively opaque.
  • 28-month-stale update from free-webmail dev with no developer name and no verified publisher status.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets QuickSearchTool as default search; all queries sent to query.quicksearchtool.com.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension calls setUninstallURL to third-party destination on removal.
  • install_url_hijack crx install_url_hijack=true; extension opens external URL on install without explicit user action.
  • privacy_policy_inadequate api Policy only 271 chars; scope_extension=false, data_collection=false, retention=false, third_party_silence=true.
  • free_webmail_no_dev_name store Developer email is tcirakovictech90@gmail.com; developer_name is empty; no verified publisher badge.
  • stale_extension store Last updated April 2, 2024; 28 months since update with 100K installs still active.
  • cookies_permission_with_search_override manifest cookies permission paired with search provider override enables per-user query tracking across all searches.
  • no_csp manifest content_security_policy is null; no CSP declared for MV3 extension (MV3 has strict default, no v2 penalty applied).

Permissions Breakdown

  • tabs medium Can read tab URLs and titles across all open tabs.
  • storage low Local key-value storage; low standalone risk.
  • declarativeNetRequest medium Can redirect or block network requests via rules.
  • cookies high Can read/write cookies scoped to quicksearchtool.com; combined with search override enables session tracking.
  • chrome_settings_overrides.search_provider high Sets itself as default search engine, redirecting all address-bar queries through query.quicksearchtool.com.
  • *://*.quicksearchtool.com/* medium Host permission scoped to own domain; enables cookie access and request interception on that domain.
  • *://query.quicksearchtool.com/* medium Narrowed to query subdomain; all search terms transit this endpoint.

Pillar Scores

Permissions6.50
Reputation7.50
Network3.00
Webstore8.50
Maintenance8.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 08:06
Listing SHA 35d6a1777324…
Force block — not fired
Score recovered no
Elapsed