Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Web Bear Search

khoapclcikhbeaggmmfcnckcnhfniijj
Risk Score
5.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 100,000
Rating 1.3
Last updated 2026-03-30 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer jamesgriffin2512@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override forces all queries through webbearsearch.com — persistent monetization/surveillance vector.
  • Developer is free-webmail (gmail) with no developer name — unverifiable identity despite verified_publisher badge.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — D/v3.5 Rule applies (+10).
  • Rating of 1.3 across installs of 100,000 signals strong user dissatisfaction; consistent with unwanted search hijack.
  • Uninstall URL hijack present — extension redirects on uninstall, a known low-effort monetization shell signal.

Evidence

  • search_provider_override manifest chrome_settings_overrides forces default search to webbearsearch.com with keyword 'wbs'; persistent query capture.
  • free_webmail_dev_no_name store Developer email jamesgriffin2512@gmail.com; developer_name empty; no verified business identity.
  • privacy_policy_inadequate api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true — generic, admits sharing, not scoped.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension sets uninstall redirect URL — monetization shell indicator.
  • low_rating store Rating 1.3 with 100,000 installs; extremely low rating signals unwanted behavior / forced search replacement.
  • verified_publisher_free_webmail store verified_publisher=true but email is gmail.com; discount capped per invariant 0c (free webmail floor).
  • webstore_search_override_monetization manifest is_default=true search override with 100K installs is classic search-monetization pattern.
  • no_csp manifest content_security_policy=null; MV3 default applies, no added penalty but noted alongside declarativeNetRequest.

Permissions Breakdown

  • storage low Stores extension settings locally; minimal risk.
  • declarativeNetRequest medium Can modify/redirect network requests; enforces search override.
  • chrome_settings_overrides.search_provider medium Forces default search engine to webbearsearch.com; monetization vector at scale.
  • host_permissions: *://webbearsearch.com/* low Scoped to developer own domain only; not broad.

Pillar Scores

Permissions6.00
Reputation7.50
Network0.00
Webstore8.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 14:52
Listing SHA 3f3ce352f25f…
Force block — not fired
Score recovered no
Elapsed