Search for a Cause
eeiiknnphladbapfamiamfimnnnodife
Risk Score
5.65
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension is 48 months stale (>36mo): abandoned or untouched since Aug 2022, maximum maintenance risk.
- Default search provider override silently routes all searches through tab.gladly.io — charity or not.
- Privacy policy fetched but scope_extension=false and third_party_silence=true; does not cover this extension.
- Uninstall URL hijack flag set; extension registers an uninstall callback to a third-party URL.
- Developer name absent from store listing; reduced accountability.
Evidence
- search_provider_override_default manifest chrome_settings_overrides sets is_default=true, routing all searches to https://tab.gladly.io/search
- uninstall_url_hijack crx uninstall_url_hijack=true; extension registers setUninstallURL callback to third-party destination.
- months_since_update_48 store Last updated August 2022; 48 months stale — maximum maintenance score triggered.
- privacy_policy_not_extension_scoped api Privacy policy fetched but scope_extension=false, data_collection=false, third_party_silence=true.
- no_developer_name store developer_name is empty string; no Offered By identity in listing.
- rating_below_4 store Rating 3.8 — below 4.0 threshold; user satisfaction concern.
- no_cve_no_bad_hosts api cve_findings_raw empty, bad_host_hits empty, monetization_hits empty — no active threat-intel hits.
- js_external_host_single crx Single external JS host: tab.gladly.io — same domain as search provider; not a broad CDN.
Permissions Breakdown
- chrome_settings_overrides.search_provider (is_default: true) medium Overrides the default search engine; redirects all search queries through tab.gladly.io.
Pillar Scores
Permissions2.00
Reputation6.00
Network0.00
Webstore5.00
Maintenance10.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:26
Listing SHA
41648c2ec739…
Force block
— not fired
Score recovered
no
Elapsed
—