Search Toggler
hodgcolihbmeagfcfpdfpnapfflmpbkb
Risk Score
5.13
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Default search engine override routes all user searches through searchtoggler.com — high exfil surface.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
- No developer name listed; developer identity accountability is low.
- Extension is 15 months stale (6–24mo maintenance band); no active update cadence.
- Privacy policy does not scope data to this extension specifically; broad third-party sharing disclosed.
Evidence
- search_provider_override manifest chrome_settings_overrides sets is_default=true, routing searches to https://searchtoggler.com/ext/search.
- privacy_policy_inadequate api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true, retention=false.
- no_developer_name store developer_name is empty string; no 'Offered by' identity on store listing.
- maintenance_stale store Last updated May 21 2025; 15 months since update — falls in 6-24mo band (+6.0 maintenance).
- no_csp manifest content_security_policy is null; MV3 has strict default so no MV2 penalty applied.
- clean_code crx code_findings_raw empty, obfuscation_score=0.0, 2 JS files scanned — no malicious signals found.
- no_bad_hosts api threat_intel bad_host_hits, monetization_hits, affiliate_hits all empty.
- operator_cluster_clean api sibling_count=0; no cluster amplifier applied.
Permissions Breakdown
- storage low Stores extension settings locally; low risk.
- declarativeNetRequest medium Can modify network requests via rules; medium risk without broad host access.
- chrome_settings_overrides.search_provider (is_default=true) high Sets itself as the default search engine, routing all searches through searchtoggler.com.
- host_permissions: https://searchtoggler.com/* medium Scoped to own domain only; enables extension-to-server communication.
Pillar Scores
Permissions4.00
Reputation6.00
Network2.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 08:05
Listing SHA
a3107f48ca23…
Force block
— not fired
Score recovered
no
Elapsed
—