Context Menu Search
ocpcmghnefmdhljkoiapafejjohldoga
Risk Score
4.46
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy (myaccount.google.com) — not scoped to this extension at all; scores as generic non-scoped policy with data_collection+third_party_sharing admitted.
- 11 distinct external JS hosts contacted including dodopayments.com (payment processor) and two backend hosts on render/vercel — unusually broad for a context-menu utility.
- No CSP declared (MV3 so no +2 penalty, but broad network surface with no policy constraint).
- months_since_update=14 with installs=100k; stale maintenance window increases supply-chain risk.
- Developer name absent; email on ashu.co.in subdomain; no verified publisher badge despite verified_publisher=true — v3.5 invariant 0c caps discount due to monetization-adjacent host (dodopayments.com).
Evidence
- privacy_policy_generic store Policy URL is Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.
- external_hosts_broad crx 11 external JS hosts: dodopayments.com, context-menu-search-backend on render+vercel, plus search engines. >3 distinct domains → +1.5 Network.
- no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP declared.
- maintenance_stale store Last updated April 2025; months_since_update=14 → Maintenance +6.0 (6-12mo band).
- install_url_hijack crx install_url_hijack=true but install_url_target=null — fires onInstalled navigation; target not captured.
- dodopayments_host crx customer.dodopayments.com in js_external_hosts; payment processor contact from a search utility is anomalous.
- verified_publisher store verified_publisher=true; discount capped at -1.0 per invariant 0c (monetization_hits path via dodopayments).
- search_engine_count_3 crx search_engine_count=3 (bing, google, yahoo); detected_category=Productivity not NewTab so C-rule does not apply.
Permissions Breakdown
- contextMenus low Core function — adds right-click search entries; low privilege.
- storage low Stores user preferences locally; no exfil risk alone.
- offscreen low MV3 offscreen document for DOM tasks; limited scope.
- sidePanel low Displays search results in side panel; UI-only capability.
Pillar Scores
Permissions1.20
Reputation4.00
Network5.00
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA
e7c636c6c104…
Force block
— not fired
Score recovered
no
Elapsed
24.0s