Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

My Safe Search

mnjfkkfifjfpcldggnigipnffkhaibda
Risk Score
4.93
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Other
Installs 1,000
Rating 3.5
Last updated 2024-02-28 (31 months ago)
Manifest version MV3
CSP present ❌ no
Developer developer@mysafesearch.co
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override forces mysafesearch.co as default; uninstall+install URL hijacks detected.
  • Extension is 31 months stale (zombie) — elevated takeover/supply-chain risk.
  • Uninstall URL hijack and install URL hijack patterns present — traffic monetization signal.
  • declarativeNetRequestWithHostAccess enables network request interception/redirect.
  • No developer name listed despite verified publisher badge; confirmed owner = false on brand check.

Evidence

  • search_provider_override_default manifest chrome_settings_overrides sets is_default=true to mysafesearch.co — high-risk search hijack capability.
  • uninstall_and_install_url_hijack crx uninstall_url_hijack=true and install_url_hijack=true — classic traffic-monetization shell signals.
  • stale_zombie_extension store 31 months since last update; >24mo threshold triggers zombie+booster scoring.
  • declarativeNetRequestWithHostAccess manifest HIGH-impact permission enabling network request interception paired with search override.
  • dom_xss_sink crx innerHTML assigned from variable in contentScriptSearch.js — DOM-XSS risk, no CSP present.
  • external_host_yahoo_search crx js_external_hosts includes search.yahoo.com — search redirect to Yahoo ad-monetization endpoint.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; small install base with high-tier permissions.
  • no_developer_name store developer_name is empty; verified_publisher=true but confirmed_owner=false on brand check.

Permissions Breakdown

  • storage low Stores local extension settings; low-risk.
  • contextMenus low Adds right-click menu entries; low capability.
  • declarativeNetRequestWithHostAccess high Can intercept and redirect network requests; HIGH-impact capability.
  • alarms low Schedules background tasks; low-risk.
  • host_permissions: *://mysafesearch.co/* low Scoped to own domain only; acceptable for search provider.
  • chrome_settings_overrides.search_provider (is_default: true) high Forces default search engine change; HIGH-risk override capability.
  • content_scripts: *://*.search.mysafesearch.co/* + *://mysafesearch.co/* low Scoped to own domain only; limited reach.

Pillar Scores

Permissions6.50
Reputation4.50
Network2.00
Webstore8.50
Maintenance8.50
Privacy0.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 12:34
Listing SHA 7eb6dd1b8a2f…
Force block — not fired
Score recovered no
Elapsed