OmniSearch
djgflnccplcmifemnpgnkkdblihncpmm
Risk Score
6.47
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Search-provider override routes all queries to defaultsearch.co (adaware ecosystem) — classic search hijack.
- Uninstall URL hijack: extension sets custom uninstall URL to third-party destination.
- Privacy policy (adaware.com) not scoped to this extension, admits data collection and third-party sharing.
- Extension is 51 months stale (MV3 but abandoned since May 2022) with 80K active installs still exposed.
- JS external hosts include flow.lavasoft.com and mynewtab.co — Lavasoft/adaware monetization infrastructure.
Evidence
- search_provider_override manifest chrome_settings_overrides sets default search to defaultsearch.co/?sp=11&q={searchTerms}, routing all queries through adaware monetization.
- uninstall_url_hijack crx uninstall_url_hijack=true; extension registers a third-party uninstall URL, tracking removal events.
- privacy_policy_inadequate api Policy fetched from adaware.com: scope_extension=false, data_collection=true, third_party_sharing=true, retention=false.
- stale_extension store Last updated May 2022 (51 months ago); 80K installs still active on abandoned codebase.
- external_hosts_adaware crx JS external hosts: flow.lavasoft.com (Lavasoft/adaware telemetry) and mynewtab.co.
- shell_pattern_description store description_promise.is_shell_pattern=true; vague promise ('fast access to search results') masks search hijack function.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; developer identity is 'omnisearch' with avq.co domain.
- triple_stale_fingerprint store v2 calibration: >24mo stale + MV3 + no CVEs but Lavasoft-associated infra; +2.0 webstore triple-stale applied.
Permissions Breakdown
- storage low Stores extension settings locally; minimal risk.
- chrome_settings_overrides.search_provider (is_default=true) medium Forces default search engine to defaultsearch.co; classic search-hijack vector.
- host_permissions: https://flow.lavasoft.com/* medium Lavasoft adware-associated domain; outbound data channel risk.
- host_permissions: https://defaultsearch.co/* medium Monetized search provider; redirects user queries.
- host_permissions: https://in.adaware.com/* medium Adaware tracking/telemetry endpoint; data exfil channel.
Pillar Scores
Permissions4.00
Reputation5.50
Network2.00
Webstore7.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:31
Listing SHA
db12deeec2fd…
Force block
— not fired
Score recovered
no
Elapsed
—