Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Free Search Engine Launcher

kpabhcileaggdidcbpolkkgmggklkpdn
Risk Score
7.55
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 14
Rating
Last updated 2022-12-07 (44 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@feshad.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override to feshad.com — a domain that does not resolve — silently hijacks all user searches.
  • declarativeNetRequestWithHostAccess + *://*/* enables blanket network request interception/redirect across all sites.
  • Privacy policy is Google's own policy (not scoped to this extension); admits data collection and third-party sharing.
  • Extension is 44 months stale with only 14 installs — abandoned, unverifiable developer, high tail-attack-surface.
  • Content script injected on all URLs paired with DOM-XSS sink (innerHTML from variable) and no CSP.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets feshad.com as default search engine; domain does not resolve per threat_intel.
  • broad_host_permissions manifest host_permissions *://*/* + content_scripts <all_urls> + declarativeNetRequestWithHostAccess = maximum reach.
  • generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, 3rd-party sharing=true.
  • developer_domain_not_resolving api feshad.com does not resolve; developer domain is unreachable, accountability is nil.
  • stale_extension store Last updated December 2022; 44 months since update — exceeds >36mo max-stale threshold.
  • dom_xss_sink_no_csp crx innerHTML assignment from variable in main.js; csp_present=false amplifies DOM-XSS risk.
  • small_install_high_perm_anomaly api Only 14 installs with HIGH-tier permissions; install_perm_anomaly flags small_install_high_perm and tail_attack_surface.
  • js_external_hosts_bing_yahoo crx js_external_hosts includes bing.com and yahoo.com alongside feshad.com — 2 search engines contacted.

Permissions Breakdown

  • declarativeNetRequestWithHostAccess high Can intercept and redirect network requests on all URLs — combined with *://*/* this is very broad.
  • storage low Standard local data persistence; low standalone risk.
  • *://*/* (host_permissions) high Broad host access across all URLs amplifies declarativeNetRequestWithHostAccess risk.
  • <all_urls> (content_scripts) high Content script injected into every page; can read/modify page content universally.
  • search_provider override (chrome_settings_overrides) medium Silently sets feshad.com as default search engine; monetization/redirect risk.

Pillar Scores

Permissions8.00
Reputation6.50
Network4.50
Webstore7.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:19
Listing SHA 119b867b9fa5…
Force block — not fired
Score recovered no
Elapsed