Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Freshy Search

oikgbpcmdphfkhplgkfngjilemlolann
Risk Score
6.93
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs 10,000
Rating 3.5
Last updated 2024-06-12 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer FreshySearch@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override routes ALL user queries to developer-controlled freshysearch-api.net.
  • Uninstall URL hijack detected — tracks user departures via third-party endpoint.
  • Developer uses free Gmail account; no verified publisher or business identity.
  • 26 months since last update — zombie extension with 10K installs still active.
  • Privacy policy not scoped to this extension and does not disclose data collection; third-party sharing undisclosed.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets default search to https://search.freshysearch-api.net/search/{searchTerms}
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension calls setUninstallURL to track user departures.
  • free_webmail_developer store Developer email FreshySearch@gmail.com; no verified publisher badge; no business domain.
  • stale_extension store Last updated June 12, 2024; 26 months since update with 10K installs still active.
  • privacy_policy_inadequate api Policy fetched but scope_extension=false, data_collection=false, retention=false; third_party_silence=true.
  • content_script_yahoo_search manifest Content script runs on search.yahoo.com/yhs/search?hspart=tro* — Yahoo affiliate monetization pattern.
  • no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP declared.
  • is_featured_by_google store Google Featured badge present, partially mitigates reputation risk.

Permissions Breakdown

  • cookies high Can read/write cookies across hosts permitted; combined with host access amplifies risk.
  • storage low Local extension storage only; low standalone risk.
  • tabs medium Can read tab URLs and titles across browser; facilitates browsing surveillance.
  • search medium Allows overriding default search engine programmatically.
  • declarativeNetRequest medium Can redirect/block network requests declaratively without inspecting content.
  • *://*.freshysearch-api.net/* high Broad host access to third-party API domain controlled by developer; enables data exfil.
  • chrome_settings_overrides.search_provider high Forces search engine replacement to freshysearch-api.net; all queries routed through developer.

Pillar Scores

Permissions7.00
Reputation6.50
Network4.50
Webstore7.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:13
Listing SHA 7ef76c59855c…
Force block — not fired
Score recovered no
Elapsed