Flex Search Engine
cmahifelbbglhkphmfhacamaigkcknop
Risk Score
5.14
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Search-provider override routes all user queries to flexsearchengine.com with no transparency about data handling.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension — worst-case disclosure.
- Developer name absent; 15-month stale extension with no rating signals low accountability.
- declarativeNetRequest can redirect/block network requests with no CSP present (MV3 default CSP applies but no explicit policy).
- Maintenance gap (12-24 months) raises supply-chain risk if domain ownership changes.
Evidence
- search_provider_override manifest chrome_settings_overrides sets is_default:true, routing all queries to flexsearchengine.com/ext/search.
- privacy_policy_unscoped_with_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → D(v3.5) +10.0.
- no_developer_name store developer_name is empty string; no 'Offered by' identity visible.
- stale_extension store months_since_update=15; falls in 12-24mo band (+6.0 maintenance).
- declarativeNetRequest_no_csp manifest declarativeNetRequest declared; csp_present=false (MV3 default applies, no explicit CSP).
- no_rating store Rating=0 with 9,000 installs; no user trust signal.
- search_engine_override_webstore store +2.0 webstore for search-provider override pattern.
- cve_findings_empty crx No CVEs detected in bundled JS libraries; CVE pillar=0.
Permissions Breakdown
- storage low Stores local preferences; no cross-origin access.
- declarativeNetRequest medium Can intercept/block/redirect network requests via static rules.
- chrome_settings_overrides.search_provider (is_default:true) medium Silently replaces default search engine; all queries routed to flexsearchengine.com.
- host_permissions: https://flexsearchengine.com/* low Scoped to single developer-owned domain only.
Pillar Scores
Permissions3.50
Reputation6.00
Network2.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 05:34
Listing SHA
fe9a89198438…
Force block
— not fired
Score recovered
no
Elapsed
—