AerateFinder
ggfpkajpmdihdfmdecfdflpmdoaegcpa
Risk Score
6.27
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Search provider override to oavsrchrdr.com hijacks all user searches through opaque third-party ad-tech domain.
- Uninstall URL hijack active — extension redirects user on removal to undisclosed third-party URL.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
- Free-webmail developer with no verified identity, no developer name, and only 3 installs — classic tail-attack surface.
- webRequest permission combined with broad search redirect enables full surveillance of user queries.
Evidence
- search_provider_override manifest chrome_settings_overrides sets default search to oavsrchrdr.com with is_default:true; third-party ad redirect domain.
- uninstall_url_hijack crx uninstall_url_hijack=true; target null but runtime call confirmed; user redirected on removal.
- privacy_policy_generic_admits_collection api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy.
- free_webmail_no_dev_name store developer_email=aeratefinder@gmail.com, developer_name empty; no verified business identity.
- install_perm_anomaly api 3 installs with HIGH-tier webRequest + search override; small_install_high_perm=true.
- js_external_hosts_mismatch crx JS contacts baking recipe sites (bakefromscratch.com, sallysbakingaddiction.com) unrelated to stated search function.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
- oavsrchrdr_host_permission manifest Host permission for https://*.oavsrchrdr.com/* — opaque third-party domain integral to search redirect.
Permissions Breakdown
- storage low Stores extension state locally; low standalone risk.
- webRequest high Can observe all network requests; enables traffic interception and surveillance.
- activeTab medium Access to current tab content on user interaction; moderate risk.
- host:https://*.aeratefinder.com/* medium Dev-owned domain; needed for search/suggest functions.
- host:https://*.oavsrchrdr.com/* high Third-party redirect domain used as default search; opaque ownership, monetization likely.
- chrome_settings_overrides.search_provider high Forces oavsrchrdr.com as default search engine; classic search-hijack vector.
Pillar Scores
Permissions7.50
Reputation7.50
Network2.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:38
Listing SHA
30a95c53620c…
Force block
— not fired
Score recovered
no
Elapsed
—