Browsing Protector
npdfkclmbnoklkdebjfodpendkepbjek
Risk Score
7.44
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- webRequest+webRequestBlocking on all URLs with no CSP — full request interception/modification capability over every site visited.
- Default search provider overridden to gobsearch.com (proxying Bing) — all user queries exfiltrated to third-party operator.
- Uninstall URL hijack to gobsearch.com survey and install hijack both present — classic monetization shell pattern.
- 66 months without update (MV2, no CSP) — abandoned extension with high-capability permissions is prime acquisition target.
- Privacy policy fetched but scope_extension==false with third_party_sharing==true — admits data sharing without scoping to this extension.
Evidence
- search_provider_override manifest chrome_settings_overrides sets is_default:true search to gobsearch.com/search-bing — all queries routed through operator.
- uninstall_url_hijack crx setUninstallURL targets gobsearch.com/uninstall-survey.php?appId=33 — monetization shell signal.
- install_url_hijack crx onInstalled opens third-party URL — install hijack confirmed.
- broad_host_access_no_csp manifest MV2, http://*/ + https://*/ + webRequestBlocking with csp_present==false — maximum interception surface.
- stale_mv2_no_csp store Last updated Feb 2021 (66 months). MV2 + no CSP + >36mo stale — triple-stale fingerprint.
- privacy_policy_inadequate api Policy fetched but scope_extension=false, data_collection=false, third_party_sharing=true — generic non-scoped with admitted sharing.
- dom_xss_sink crx contentScript.js: innerHTML from user-controlled variable with no CSP — DOM-XSS risk on every page.
- tail_attack_surface api 1,000 installs with HIGH-tier permissions (webRequestBlocking + all_urls) — low visibility, high capability.
Permissions Breakdown
- tabs medium Access to tab URLs/titles; combined with broad host access raises risk.
- webRequest high Intercepts all HTTP/S requests across all sites — broad surveillance capability.
- webRequestBlocking high Can block/modify requests in flight; paired with all_urls = critical capability.
- http://*/ high Broad host access to all HTTP sites; enables interception and content injection.
- https://*/ high Broad host access to all HTTPS sites; same risk surface as http.
- chrome_settings_overrides.search_provider (is_default:true) high Overrides default search engine to gobsearch.com, routing all queries through their proxy.
Pillar Scores
Permissions8.50
Reputation5.00
Network6.00
Webstore8.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-27 16:02
Listing SHA
ac536d18d820…
Force block
— not fired
Score recovered
no
Elapsed
—