Newz Finder
hfhfmkmokccaciopjahpkmfdbkjbhmfp
Risk Score
4.44
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Search provider hijacked to search.mybrowsingsafety.pro — a third-party ad-monetization endpoint, not the developer's domain.
- Uninstall and install URL hijacks both active — classic browser-hijacker behavioral fingerprint.
- Extension stale 28 months with no updates; verified-publisher discount capped to -1.0 due to months_since_update > 18.
- Privacy policy discloses data collection and third-party sharing without retention period — inadequate for scope.
- DOM-XSS sink (innerHTML) in popup.js with no CSP; amplifies attack surface if search provider serves malicious content.
Evidence
- search_provider_override manifest chrome_settings_overrides sets default search to search.mybrowsingsafety.pro — third-party monetization domain, not developer domain.
- uninstall_url_hijack crx uninstall_url_hijack=true; install_url_hijack=true — both hijack patterns present, typical browser-hijacker cluster.
- stale_extension store 28 months since last update (May 2024); verified-publisher discount capped at -1.0 per invariant 0c (>18mo stale).
- no_developer_name store developer_name is empty string; reduces accountability signal.
- privacy_policy_inadequate api Policy scoped, collects data, shares with third parties, but retention not disclosed — privacy pillar +1.0 for retention gap.
- dom_xss_sink_no_csp crx innerHTML from user-controlled var in popup.js; csp_present=false triggers FIX B elevation to +2.0.
- search_override_webstore_penalty manifest Search-provider override scored +2.0 in Webstore (monetization shape); stacked with install/uninstall hijack +3.0 each.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discounts applied but capped due to staleness >18mo.
Permissions Breakdown
- storage low Stores local settings only; low standalone risk.
- chrome_settings_overrides.search_provider medium Overrides default search engine to search.mybrowsingsafety.pro; monetization risk.
Pillar Scores
Permissions3.50
Reputation4.00
Network2.00
Webstore8.00
Maintenance6.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 05:32
Listing SHA
b634bd6d3ab6…
Force block
— not fired
Score recovered
no
Elapsed
—