Search'n Give
cooagkhjpjaoljncieegiefgphelgjhm
Risk Score
5.04
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack + install URL hijack both flagged: onboarding/offboarding traffic redirected to 3rd party.
- Search provider override sets itself as default engine (is_default:true) with only 17 installs — tail monetization risk.
- Privacy policy admits data collection + third-party sharing but is NOT scoped to this extension — highest privacy score.
- No developer name listed; verified publisher badge is sole accountability signal.
- External JS host includes react.dev (CDN), introducing remote-code-loading risk surface.
Evidence
- uninstall_url_hijack + install_url_hijack both true crx Both onInstalled and uninstall URL hooks set; standard monetization-shell fingerprint even with null targets.
- chrome_settings_overrides search_provider is_default:true manifest Extension forcibly replaces default search engine with search.searchngive.org; core revenue mechanism.
- privacy_policy scope_extension:false, data_collection:true, third_party_sharing:true api Policy admits collection+sharing but never scopes to this extension; triggers v3.5-D +10.0 privacy rule.
- js_external_hosts includes react.dev crx External CDN host; if loaded at runtime could introduce remote code; no CSP to constrain it.
- developer_name empty store No 'Offered by' name; verified_publisher is only accountability anchor.
- install_count:17 store Extremely low install count; blast radius small but tail-attack-surface concern noted.
- csp_present:false, manifest_version:3 manifest MV3 has strict default for service worker but no explicit CSP; no v2 +2.0 penalty applies.
- verified_publisher:true, domain resolves, looks_throwaway:false api Publisher verified; domain live; mitigates reputation partially but privacy/hijack signals override.
Permissions Breakdown
- storage low Persists local settings; no cross-origin data exposure.
- host_permission:*://search.yahoo.com/* medium Allows content-script injection on Yahoo search; read/modify search results.
- host_permission:https://www.searchngive.org/* low Dev-controlled domain; expected for settings/charity tracking.
- chrome_settings_overrides.search_provider (is_default:true) medium Silently sets default search engine; core monetization mechanism.
Pillar Scores
Permissions3.50
Reputation5.00
Network2.00
Webstore8.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:33
Listing SHA
edeb1490a1b3…
Force block
— not fired
Score recovered
no
Elapsed
—