UpSearches
ccncieedlifdlmckgmlcdfjehofcgoei
Risk Score
6.71
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Search provider override forces all searches through find.upsearches.com with tracking params; privacy-invasive monetization.
- Developer uses free Gmail; no verified publisher badge; 25-month staleness with no updates on a search-hijacking extension.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension (v3.5 rule D: +10.0 privacy).
- Uninstall URL hijack detected; extension redirects users on removal to a developer-controlled endpoint.
- External JS host webinline-usage.streamesh.net is an unrecognized third-party domain embedded alongside developer hosts.
Evidence
- search_provider_override manifest chrome_settings_overrides sets UpSearches as default search engine with is_default:true; all queries routed to find.upsearches.com.
- uninstall_url_hijack crx uninstall_url_hijack=true; extension registers a removal redirect, a known monetization/tracking tactic.
- free_webmail_developer store Developer email upsearches@gmail.com; no verified publisher badge; raises accountability concerns.
- privacy_policy_generic api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true; admits sharing without extension scope.
- stale_extension store Last updated July 2024; 25 months since update on a search-override extension with 8,000 installs.
- unknown_external_host crx js_external_hosts includes webinline-usage.streamesh.net; unrecognized third-party domain alongside developer hosts.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; low install count combined with high-tier permissions increases acquisition-risk.
- no_csp manifest content_security_policy is null; MV3 has strict defaults but absence of explicit CSP noted alongside external host contacts.
Permissions Breakdown
- declarativeNetRequest medium Can block/redirect network requests; lower risk than webRequest but still significant.
- storage low Standard local data persistence; minimal standalone risk.
- scripting high Allows programmatic script injection into pages; broad capability.
- alarms low Scheduling only; low direct risk.
- webRequest high Observe and intercept network requests; high surveillance capability.
- chrome_settings_overrides.search_provider (is_default:true) high Forces UpSearches as default search engine; monetization/data capture mechanism.
- host_permissions: https://*.upsearches.com/* medium Scoped to own domain; narrows risk but enables full read/write on developer infrastructure.
Pillar Scores
Permissions7.00
Reputation7.00
Network4.50
Webstore8.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:33
Listing SHA
be49e7b13d8d…
Force block
— not fired
Score recovered
no
Elapsed
—