My Search Easy
ebnkenjcbhmpapihbcnfebfgclipllgj
Risk Score
5.05
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing (v3.5 D: +10.0 privacy).
- Google brand impersonation: description claims to put Google search on homepage; developer is not Google (is_impersonation=true).
- Startup-page override hijacks browser homepage to mysearcheasy.com — search monetization mechanism.
- Install URL hijack: onInstalled redirects to https://www.mysearcheasy.com/sucess.htm (3rd-party install hook).
- Stale extension: 15 months since update, MV3, no CSP declared.
Evidence
- startup_page_override manifest chrome_settings_overrides.startup_pages set to https://mysearcheasy.com/search/ — homepage hijack for search monetization.
- brand_impersonation store brand_mention.is_impersonation=true; brands=['google']; developer domain mysearcheasy.com is not Google; not verified publisher.
- install_url_hijack crx install_url_hijack=true; target=https://www.mysearcheasy.com/sucess.htm — opens 3rd-party page on install.
- generic_privacy_policy store Policy URL is Google's own privacy page; scope_extension=false, data_collection=true, third_party_sharing=true — v3.5 D applies (+10.0).
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; developer is mysearcheasy with no recognized org discount.
- stale_extension store months_since_update=15; maintenance pillar +6.0 (12-24mo band).
- no_csp manifest content_security_policy=null; csp_present=false on MV3 — no additional network penalty but noted.
- js_external_hosts crx js_external_hosts=['www.mysearcheasy.com'] — single dev-controlled domain, limited network risk.
Permissions Breakdown
- chrome_settings_overrides.startup_pages medium Overrides browser startup page to mysearcheasy.com — monetization vector, not declared in permissions[].
Pillar Scores
Permissions3.00
Reputation7.00
Network0.00
Webstore6.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 05:33
Listing SHA
f26f998af8f6…
Force block
— not fired
Score recovered
no
Elapsed
—