Health Search Pro
fmmickkobhbfclcaejbkbkfjejpddfjg
Risk Score
7.10
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Default search engine hijacked to ofsrchrdr.com — a third-party ad/monetization redirector, not the developer's own domain.
- Uninstall URL hijack detected; extension redirects users upon removal, classic search-hijacker fingerprint.
- Privacy policy fetched but not scoped to this extension; admits data collection and third-party sharing — worst-case disclosure.
- Free-webmail developer (gmail), no developer name, no verified publisher — anonymous high-capability actor.
- webRequest permission combined with search-provider override enables full query interception and monetization of all user searches.
Evidence
- search_provider_override manifest is_default=true, search_url routes to ofsrchrdr.com with tracking param dgd=RD1005463; third-party monetization redirector.
- uninstall_url_hijack crx uninstall_url_hijack=true; extension registers an uninstall redirect — common search-hijacker pattern.
- privacy_policy_generic api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — admits collection without extension scope.
- developer_identity store developer_email=healthsearchpro@gmail.com, developer_name empty, verified_publisher=false, is_featured=false.
- webRequest_high_permission manifest webRequest declared alongside search-provider override; can intercept all queries routed through hijacked engine.
- rating_signal store Rating=1.0 — worst possible rating; indicates user-reported harm or dissatisfaction.
- maintenance_stale store months_since_update=14; falls in 12-24 month band (+6.0 maintenance score).
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; low-install extension with high-tier permissions.
Permissions Breakdown
- storage low Stores extension preferences; low risk alone.
- webRequest high Can observe and intercept all network requests; major surveillance capability.
- activeTab medium Access to currently active tab content on user interaction.
- https://*.healthsearchpro.com/* medium Scoped host access to dev domain; moderate risk, enables data exfil to controlled server.
- https://*.ofsrchrdr.com/* high Third-party search redirector domain used as default search — not dev-controlled identity.
- chrome_settings_overrides.search_provider (is_default:true) high Forces default search engine to ofsrchrdr.com, a monetization redirector; high-impact override.
Pillar Scores
Permissions7.00
Reputation8.50
Network4.00
Webstore9.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 06:15
Listing SHA
19020a10a9c0…
Force block
— not fired
Score recovered
no
Elapsed
—