RealSearch - Human Answers Only (No AI Spam)
jodmdafccdbmmonjcmckddlaplcigcjl
Risk Score
5.19
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Free-webmail dev (bigdeveloper44@gmail.com) + no developer name + no business domain = high anonymity risk.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits broad data collection and 3rd-party sharing.
- External JS host 'chromecrxstore.com' is unrecognized/suspicious; HK geo-diversity adds concern.
- Brand impersonation: 'reddit' mentioned in description; developer not confirmed owner.
- install_url_hijack flagged true; low install count (24) with multi-search-engine host access across 9 engines.
Evidence
- free_webmail_dev_no_name store Developer email bigdeveloper44@gmail.com; developer_name empty; no business domain.
- generic_google_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- suspicious_external_js_host crx js_external_hosts includes chromecrxstore.com — unrecognized domain, hosted in HK.
- brand_impersonation store brand_mention.is_impersonation=true for 'reddit'; developer not confirmed owner.
- install_url_hijack crx install_url_hijack=true; extension opens external URL on install.
- multi_search_engine_contact manifest search_engine_count=9; host_permissions span 9 distinct search engines including Yandex and Baidu.
- verified_publisher_featured_but_gmail store verified_publisher=true and is_featured_by_google=true but dev is anonymous free-webmail; reputation floor applies.
- no_csp crx content_security_policy=null on MV3; csp_present=false.
Permissions Breakdown
- contextMenus low Adds right-click menu items; minimal privilege.
- *://www.google.com/* medium Content-script access to Google search pages; matches stated function.
- *://www.bing.com/* medium Content-script access to Bing; matches stated function.
- *://*.duckduckgo.com/* medium Content-script access to DuckDuckGo; matches stated function.
- *://*.yahoo.com/* medium Content-script access to Yahoo search; matches stated function.
- *://*.yahoo.co.jp/* medium Content-script access to Yahoo Japan; matches stated function.
- *://*.yahoo.co.in/* medium Content-script access to Yahoo India; matches stated function.
- *://search.brave.com/* medium Content-script access to Brave search; matches stated function.
- *://www.ecosia.org/* medium Content-script access to Ecosia; matches stated function.
- *://www.baidu.com/* medium Content-script access to Baidu; matches stated function.
- *://*.yandex.com/* medium Content-script on Yandex; Russian search engine, elevated geo-risk.
- *://*.yandex.ru/* medium Content-script on Yandex.ru; Russian TLD, elevated geo-risk.
- https://suggestqueries.google.com/* low Read-only Google autocomplete API; low risk.
Pillar Scores
Permissions3.00
Reputation7.50
Network2.00
Webstore6.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 15:49
Listing SHA
d2f1c5075f04…
Force block
— not fired
Score recovered
no
Elapsed
—