Free Search Engine Launcher
kpabhcileaggdidcbpolkkgmggklkpdn
Risk Score
7.55
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Search provider override to feshad.com — a domain that does not resolve — silently hijacks all user searches.
- declarativeNetRequestWithHostAccess + *://*/* enables blanket network request interception/redirect across all sites.
- Privacy policy is Google's own policy (not scoped to this extension); admits data collection and third-party sharing.
- Extension is 44 months stale with only 14 installs — abandoned, unverifiable developer, high tail-attack-surface.
- Content script injected on all URLs paired with DOM-XSS sink (innerHTML from variable) and no CSP.
Evidence
- search_provider_override manifest chrome_settings_overrides sets feshad.com as default search engine; domain does not resolve per threat_intel.
- broad_host_permissions manifest host_permissions *://*/* + content_scripts <all_urls> + declarativeNetRequestWithHostAccess = maximum reach.
- generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, 3rd-party sharing=true.
- developer_domain_not_resolving api feshad.com does not resolve; developer domain is unreachable, accountability is nil.
- stale_extension store Last updated December 2022; 44 months since update — exceeds >36mo max-stale threshold.
- dom_xss_sink_no_csp crx innerHTML assignment from variable in main.js; csp_present=false amplifies DOM-XSS risk.
- small_install_high_perm_anomaly api Only 14 installs with HIGH-tier permissions; install_perm_anomaly flags small_install_high_perm and tail_attack_surface.
- js_external_hosts_bing_yahoo crx js_external_hosts includes bing.com and yahoo.com alongside feshad.com — 2 search engines contacted.
Permissions Breakdown
- declarativeNetRequestWithHostAccess high Can intercept and redirect network requests on all URLs — combined with *://*/* this is very broad.
- storage low Standard local data persistence; low standalone risk.
- *://*/* (host_permissions) high Broad host access across all URLs amplifies declarativeNetRequestWithHostAccess risk.
- <all_urls> (content_scripts) high Content script injected into every page; can read/modify page content universally.
- search_provider override (chrome_settings_overrides) medium Silently sets feshad.com as default search engine; monetization/redirect risk.
Pillar Scores
Permissions8.00
Reputation6.50
Network4.50
Webstore7.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:19
Listing SHA
119b867b9fa5…
Force block
— not fired
Score recovered
no
Elapsed
—