View Menu with Prices
ijbmkpeacbkgpfkomjbionjgdhbmlpfp
Risk Score
4.72
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Default search engine override routes all user searches to developer-controlled domain (viewmenuprices.com).
- Uninstall URL hijack confirmed — tracks user uninstall events via third-party redirect.
- Install URL hijack opens developer site on install — monetization/tracking pattern.
- Privacy policy admits third-party data sharing but lacks retention disclosure.
- No ratings, unverified developer, narrow-purpose domain controlling search traffic.
Evidence
- search_provider_override manifest chrome_settings_overrides sets is_default=true; all searches routed to viewmenuprices.com/auto-suggest/search.php
- uninstall_url_hijack crx uninstall_url_hijack=true; target null but hijack flag set — tracks uninstall lifecycle.
- install_url_hijack crx install_url_hijack=true; target https://viewmenuprices.com/extension-success/ — monetization/redirect pattern.
- privacy_policy_third_party_sharing api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false, rating=0 with 0 reviews.
- maintenance_stale store months_since_update=7; falls in 3-6 month band (+1.5).
- webstore_install_count store 10,000 installs with search-override monetization shape raises blast-radius concern.
- csp_absent_mv3 manifest content_security_policy=null; MV3 provides strict default so no network penalty applied.
Permissions Breakdown
- chrome_settings_overrides.search_provider (is_default=true) medium Overrides default search engine to developer-controlled endpoint; intercepts all user searches.
Pillar Scores
Permissions4.00
Reputation5.00
Network0.00
Webstore8.50
Maintenance3.50
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 08:04
Listing SHA
187771f95aaf…
Force block
— not fired
Score recovered
no
Elapsed
—