Best House Search
kfpgdllicalahckijjnlidfejgfenghp
Risk Score
6.75
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Default search engine hijacked to besthouseclub.com via chrome_settings_overrides with no user prompt.
- Developer uses free Gmail with no developer name — anonymous actor controlling search for 3,000 users.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
- Extension stale 27 months (no updates) with search-override capability still active.
- Uninstall URL hijack flagged — extension redirects browser on removal to undisclosed third-party URL.
Evidence
- search_provider_override manifest chrome_settings_overrides sets besthouseclub.com as default search engine (is_default=true).
- uninstall_url_hijack crx uninstall_url_hijack=true; target null in listing but runtime call confirmed in CRX.
- free_webmail_dev_no_name store Developer email jgarcia42616@gmail.com; developer_name empty; no verifiable business identity.
- privacy_policy_inadequate api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — worst-case generic policy.
- stale_extension store Last updated May 2024; 27 months since update with active search override capability.
- verified_publisher_claimed store verified_publisher=true but developer_name empty and email is free webmail; trust discount capped.
- declarativeNetRequest_with_search_override manifest declarativeNetRequest combined with default search override enables request-level manipulation of search traffic.
- no_csp manifest content_security_policy=null; csp_present=false on MV3 extension.
Permissions Breakdown
- storage low Stores extension settings locally; low risk in isolation.
- declarativeNetRequest medium Can modify network requests; medium risk, no broad host access paired.
- host_permission: *://besthouseclub.com/* low Scoped to single dev-controlled domain; low blast radius.
- chrome_settings_overrides.search_provider (is_default=true) high Silently overrides default search engine to dev-controlled domain; high abuse potential.
Pillar Scores
Permissions5.00
Reputation7.50
Network2.50
Webstore8.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:57
Listing SHA
0834fb260050…
Force block
— not fired
Score recovered
no
Elapsed
—