Change Default Search Engine
cfikbclbljhmmokgdokgjhnpinnmihkp
Risk Score
5.06
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Search provider override routes all user queries through developer-controlled default-search.site with no scoping disclosure.
- Host permission to 'ext-ads-mvp.captain-products.workers.dev' indicates ad-serving infrastructure bundled into a search-changer.
- Privacy policy is Google's own generic policy — does not scope to this extension; admits data collection and 3rd-party sharing.
- Bundled jquery@2.1.4 has 4 medium-severity CVEs (XSS); unfixed well past patched versions.
- Free-webmail dev email (numbered alias), no developer name — unaccountable publisher despite verified/featured badges.
Evidence
- search_provider_override_is_default manifest chrome_settings_overrides.search_provider.is_default=true routes all search to default-search.site.
- ad_infra_host_permission manifest host_permissions includes ext-ads-mvp.captain-products.workers.dev — 'ads-mvp' signals monetization infra.
- generic_google_privacy_policy store Privacy policy URL is myaccount.google.com/privacypolicy — not scoped to this extension; admits 3rd-party sharing.
- jquery_cve_bundle crx jquery@2.1.4 bundled with 4 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251).
- free_webmail_numbered_alias_dev store Developer email jeff38399green@gmail.com is a numbered free-webmail alias; no developer name provided.
- ad_ninja_skipply_external_js_hosts crx js_external_hosts includes ad-ninja.net and skipply.net — known ad/tracking domains.
- verified_and_featured_but_numbered_alias store Verified publisher and featured badges coexist with numbered free-webmail email and absent developer name.
- dom_xss_sink_in_vulnerable_jquery crx innerHTML DOM-XSS sink in jquery@2.1.4 which also carries 4 unpatched medium CVEs — compounded risk.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.1.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.1.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.1.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.1.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- unlimitedStorage low Allows unlimited local storage; low standalone risk.
- storage low Basic key-value storage, standard for extensions.
- declarativeNetRequest medium Can intercept/redirect network requests; medium risk without <all_urls>.
- host_permission: https://default-search.site/ medium Grants access to the custom search endpoint operated by developer.
- host_permission: https://ext-ads-mvp.captain-products.workers.dev/* high 'ads-mvp' in hostname strongly suggests ad-serving infra; not typical for a search changer.
- chrome_settings_overrides.search_provider (is_default: true) high Replaces the default search engine with developer-controlled endpoint; high monetization/data risk.
Pillar Scores
Permissions6.50
Reputation6.50
Network3.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality3.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 04:35
Listing SHA
5f52b8b40592…
Force block
— not fired
Score recovered
no
Elapsed
—