DuckDuckGo No-AI Search
faoilnlkccdjdkpljainiiimmijofmpd
Risk Score
3.15
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but scope_extension==false and admits third-party sharing — not scoped to this extension.
- Search provider override routes all default searches to noai.duckduckgo.com without verified publisher badge.
- No developer name listed in store despite using duckduckgo.com domain email — unverified identity.
- developer_domain confirmed_owner==false; brand_mention shows no impersonation confirmed, raising uncertainty.
- 30K users have default search silently redirected; any future compromise of the extension would affect all of them.
Evidence
- search_provider_override manifest chrome_settings_overrides sets is_default=true pointing to noai.duckduckgo.com for all queries.
- privacy_policy_scope_mismatch api Policy fetched (60KB) but scope_extension=false, data_collection=true, third_party_sharing=true — generic policy.
- no_developer_name store developer_name is empty; verified_publisher=false; is_featured_by_google=false.
- no_js_files crx js_file_count=0, code_findings_raw empty, obfuscation_score=0.0 — minimal attack surface.
- no_bad_hosts api threat_intel bad_host_hits, monetization_hits, affiliate_hits all empty; domain resolves cleanly.
- no_cve_findings api cve_findings_raw is empty; no bundled JS libraries detected.
- recently_updated store months_since_update=0; maintenance pillar=0.
- brand_impersonation_check api brand_mention.is_impersonation=false; developer_domain=duckduckgo.com; confirmed_owner=false.
Permissions Breakdown
- chrome_settings_overrides.search_provider medium Sets DuckDuckGo No-AI as default search engine; routes all queries to noai.duckduckgo.com.
Pillar Scores
Permissions2.00
Reputation5.50
Network0.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:24
Listing SHA
f9a28c2c0f7c…
Force block
— not fired
Score recovered
no
Elapsed
—