Search GPT for Chrome
fmncmpginchogfdnjfeopdopoiegjjjp
Risk Score
6.10
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Hotmail dev email + generic AI-tools name: unverifiable developer identity with no accountability.
- Privacy policy is Google's own policy — does not disclose what THIS extension collects; scope_extension==false, data_collection==true, third_party_sharing==true.
- Broad host_permissions *://*/* + content_scripts on all Google TLDs expose every search query to extension code.
- External host chat.searchaitool.net contacted — unknown third-party AI backend with no disclosed data handling.
- AI extension processing search-page content at scale (10K+ users) with opaque backend and inadequate privacy disclosures.
Evidence
- free_webmail_developer store Developer email chrismartiner.90@hotmail.com is a free webmail address; no verifiable business identity.
- generic_privacy_policy store Privacy URL points to Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
- broad_host_permissions manifest host_permissions *://*/* plus content_scripts on 200+ Google TLDs and major search engines.
- unknown_ai_backend crx js_external_hosts includes chat.searchaitool.net — third-party AI backend with no disclosed ownership or data policy.
- function_constructor crx new Function() constructor in libs/math.min.js; low obfuscation score but dynamic code execution path present.
- no_csp manifest content_security_policy is null; MV3 default helps but no explicit CSP reduces defence-in-depth.
- ai_extension_page_content store AI extension injecting into all search pages; processes user search queries and sends to external backend.
- install_count_threshold store 10,000 installs with free-webmail unverified developer and inadequate privacy policy increases blast radius.
Permissions Breakdown
- storage low Local key-value storage only; low inherent risk.
- host_permissions: *://*/* high Broad host access grants content-script read/write on every site visited.
- content_scripts: *://*/*oogle.*/search + major engines high Runs code on all Google TLDs and major search engines; reads user search queries.
Pillar Scores
Permissions7.00
Reputation7.50
Network4.50
Webstore4.50
Maintenance3.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:05
Listing SHA
df485d933d09…
Force block
— not fired
Score recovered
no
Elapsed
—