Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SearchVPN

lajilhjggagbmlbkhllkeobbpgkghdmb
Risk Score
6.74
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 11
Rating
Last updated 2024-11-11 (21 months ago)
Manifest version MV3
CSP present ❌ no
Developer searchvpnextension@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override to kwsrc4you.com monetization domain — extension is a search hijacker disguised as VPN.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic policy).
  • Developer uses free Gmail with no verified publisher status; uninstall URL hijack confirmed.
  • webRequest permission allows network traffic observation across host_permissions scope.
  • 21 months without update; only 11 installs suggests abandoned or freshly dropped monetization shell.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets default search to kwsrc4you.com with affiliate param dgd=RD1005189; not a VPN function.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension registers uninstall callback to third-party URL.
  • privacy_policy_generic_admits_sharing api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) worst tier.
  • free_webmail_developer store Developer email searchvpnextension@gmail.com; no verified publisher; no business domain.
  • install_perm_anomaly api Only 11 installs with HIGH-tier permissions; small_install_high_perm=true, tail_attack_surface=true.
  • stale_extension store 21 months since last update; maintenance score elevated (6-24mo band).
  • kwsrc4you_monetization_domain manifest host_permissions include kwsrc4you.com; search URL routes queries through ad-network domain.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension.

Permissions Breakdown

  • storage low Stores extension settings locally; low standalone risk.
  • webRequest high Can observe all network requests; paired with host_permissions raises interception risk.
  • https://*.search-vpn.com/* medium Developer-owned domain; scoped but enables data exfil to own server.
  • https://*.kwsrc4you.com/* high Third-party search monetization domain used as default search provider; scope mismatch for a VPN.
  • chrome_settings_overrides.search_provider high Overrides default search engine to kwsrc4you.com (ad-monetization); is_default=true.

Pillar Scores

Permissions7.00
Reputation8.50
Network3.00
Webstore8.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:58
Listing SHA ce9c05dcd6bc…
Force block — not fired
Score recovered no
Elapsed