Mystique Search
jbmmmambjlkjkinkpifefiaehflllopg
Risk Score
3.07
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Search-provider override silently redirects all browser searches to mystiquestudio.net.
- Extension not updated in 23 months; approaching stale threshold.
- Developer name absent from listing; only email provided.
- No JS files scanned — minimal auditability but no code surface detected.
- Verified publisher but developer name omitted reduces accountability.
Evidence
- search_provider_override manifest chrome_settings_overrides sets mystiquestudio.net as default search engine with is_default=true.
- verified_publisher store Extension has verified publisher badge; domain kinner-inc.com resolves and is not throwaway.
- staleness store Last updated September 14, 2024; 23 months since update, approaching 24-month stale band.
- privacy_policy_adequate api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
- no_developer_name store developer_name field is empty; reduces accountability despite verified publisher status.
- no_js_code crx js_file_count=0, obfuscation_score=0.0, code_findings_raw empty — no executable JS surface.
- no_bad_hosts_or_cves api threat_intel bad_host_hits, monetization_hits, affiliate_hits all empty; cve_findings_raw empty.
- installs_moderate store 50,000 installs; adds +1.0 webstore reach signal.
Permissions Breakdown
- chrome_settings_overrides.search_provider medium Sets Mystique Search as default search engine; medium per rubric but is the sole function of this extension.
Pillar Scores
Permissions2.00
Reputation3.00
Network2.00
Webstore3.00
Maintenance6.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-27 16:20
Listing SHA
fbb55f1236c2…
Force block
— not fired
Score recovered
no
Elapsed
—