Tracking Package
dgehhbnnldekfdjkndgmahagcjppompb
Risk Score
5.77
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Default search engine silently redirected to onlinemypackage.com — classic search-hijack monetization.
- Privacy policy admits data collection and third-party sharing without scoping to this extension (D rule: +10.0).
- Uninstall and install URL hijacks both present — aggressive lifecycle monetization hooks.
- Extension name/domain mismatch: developer is QwerPDF but extension routes searches via onlinemypackage.com and xtracking.me.
- JS external hosts include xtracking.me — ambiguous tracking domain not related to stated function.
Evidence
- search_provider_override manifest chrome_settings_overrides sets default search to onlinemypackage.com/search-package.php; is_default=true.
- uninstall_url_hijack crx uninstall_url_hijack=true; aggressive lifecycle hook flagged by scanner.
- install_url_hijack crx install_url_hijack=true; extension opens 3rd-party page on install.
- privacy_policy_inadequate api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — D rule applies.
- external_js_host_mismatch crx js_external_hosts includes xtracking.me — unrelated to stated package-tracking function.
- developer_domain_mismatch store Developer email @qwerpdf.com; extension routes to onlinemypackage.com and xtracking.me.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; only 20 installs.
- content_scripts_yahoo_search manifest Content scripts injected into search.yahoo.com/search* enabling query capture.
Permissions Breakdown
- storage low Used to persist settings locally; low direct harm potential.
- *://search.yahoo.com/* (host_permission) medium Allows content script injection into Yahoo Search pages; scoped but enables query interception.
- chrome_settings_overrides.search_provider (is_default) high Overrides default search engine to onlinemypackage.com; core search-hijack vector.
Pillar Scores
Permissions7.00
Reputation5.50
Network2.50
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:30
Listing SHA
225fb0aa6bb1…
Force block
— not fired
Score recovered
no
Elapsed
—