MetaGer Search
gjfllojpkdnjaiaokblkmjlebiagbphd
Risk Score
3.73
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic policy (not scoped to this extension) yet admits data collection and third-party sharing — score +10.
- Developer name field is empty; no 'Offered by' display name reduces accountability.
- Search provider override sets MetaGer as default search engine without explicit user confirmation flow visible.
- Small install base (815) combined with HIGH-tier permissions (webRequest, cookies, declarativeNetRequestWithHostAccess) raises tail-attack-surface concern.
- No CSP declared (MV3 default applies, but no explicit policy) alongside webRequest/cookies on scoped hosts.
Evidence
- privacy_policy_generic_google store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10 Privacy (v3.5 D).
- verified_publisher store Extension has verified publisher badge; metager.de resolves, no monetization hits, no CVEs — full -3.0 discount applies.
- developer_name_empty store developer_name is empty string; no 'Offered by' display name visible, adding +1.0 Reputation.
- search_provider_override manifest chrome_settings_overrides sets MetaGer as default search provider; +1.0 Permissions per rubric (a).
- install_perm_anomaly api 815 installs with HIGH-tier permissions (webRequest, cookies, declarativeNetRequest); small_install_high_perm=true → +1.5 Webstore.
- no_cve_no_code_findings crx cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0 — CVE and Code Quality pillars score 0.
- host_scope_narrow manifest host_permissions and content_scripts scoped exclusively to metager.org and metager.de; no broad host access.
- threat_intel_clean api bad_host_hits=[], monetization_hits=[], affiliate_hits=[], looks_throwaway=false, geo_countries=[DE] only.
Permissions Breakdown
- storage low Standard local state persistence; low risk.
- cookies high Can read/write cookies; scoped to metager.org/de host_permissions only, limiting exposure.
- webRequest high Observe network requests; scoped to metager hosts, plausible for search provider use.
- declarativeNetRequestWithHostAccess high Can block/redirect requests; scoped to metager hosts reduces blast radius.
- alarms low Schedule background tasks; minimal risk on its own.
- host_permissions: https://metager.org/* medium Scoped to developer-owned domain; consistent with search provider function.
- host_permissions: https://metager.de/* medium Scoped to developer-owned domain; consistent with search provider function.
- chrome_settings_overrides.search_provider (is_default: true) medium Sets MetaGer as default search engine; declared function but overrides user setting.
Pillar Scores
Permissions4.50
Reputation4.00
Network2.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:22
Listing SHA
024142c4e1df…
Force block
— not fired
Score recovered
no
Elapsed
—