Pointcoin - Search & Earn
jdbelhlllpkdmeoopdhanocdfdcnaejd
Risk Score
6.27
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Default search provider override routes ALL searches through extapi.pointcoin.app — complete query interception.
- Uninstall + install URL hijacking: tracks install/uninstall lifecycle via 3rd-party redirects.
- Privacy policy admits data collection and third-party sharing without scoping to this extension — D clause +10.0.
- Content scripts injected on Google, Amazon checkout, ChatGPT, Claude, Copilot, Gemini, Grok — extremely broad sensitive-page coverage.
- Google AdSense (pagead2.googlesyndication.com) in JS hosts + 3 search engines contacted = monetization shell pattern.
Evidence
- search_provider_override manifest chrome_settings_overrides.search_provider is_default=true; routes searches to extapi.pointcoin.app/psearchx.
- uninstall_and_install_url_hijack manifest Both uninstall_url_hijack and install_url_hijack are true — lifecycle event tracking.
- monetization_host crx pagead2.googlesyndication.com in js_external_hosts; Google AdSense monetization confirmed.
- privacy_policy_generic_with_sharing api scope_extension=false, data_collection=true, third_party_sharing=true — v3.5(D) hard +10.0.
- multi_search_engine_contact crx search_engine_count=3 (bing, google, yahoo) in external hosts — ad-monetization aggregator pattern.
- content_scripts_sensitive_pages manifest Scripts on Amazon checkout, ChatGPT, Claude, Gemini, Grok, Google Search, Perplexity — high-sensitivity injection.
- trk_pubtailer_host crx trk.pubtailer.com in js_external_hosts — ad-tracking/publisher monetization network.
- no_developer_name store developer_name is empty string; no verified publisher badge; rating=1.
Permissions Breakdown
- storage low Local key-value storage; limited risk alone.
- tabs medium Can read URLs and titles of all open tabs.
- host: https://extapi.pointcoin.app/* medium Extension's own backend API; expected but tunnels search data.
- host: https://api.bing.com/* medium Bing API access; search query interception risk.
- content_scripts: search/AI/shopping/chat platforms high Scripts injected into Google, Bing, ChatGPT, Claude, Amazon checkout — broad sensitive-page access.
- chrome_settings_overrides: search_provider (is_default=true) high Overrides default search engine to extension-controlled endpoint; all searches routed through extapi.pointcoin.app.
Pillar Scores
Permissions6.00
Reputation7.00
Network4.50
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:24
Listing SHA
8c869fd55b30…
Force block
— not fired
Score recovered
no
Elapsed
—