One Click Image Search
odbanhjffpnjgcbldodeakkmcafnhema
Risk Score
2.47
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Default search provider override routes all user searches to findmypicsearches.com — persistent search-hijack risk.
- Privacy policy points to Google's generic policy; does not disclose what this extension collects, sharing, or retention.
- Developer name is blank; no 'Offered by' attribution increases accountability gap.
- Rating of 3.4 with 60K installs suggests user dissatisfaction, possibly related to search redirect behavior.
- Search provider override qualifies for MEDIUM permission risk under rubric v2a even with empty permissions[].
Evidence
- search_provider_override manifest chrome_settings_overrides sets default search to quick.findmypicsearches.com and suggest to recommend.findmypicsearches.com.
- generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension at all.
- privacy_policy_classification api scope_extension=false, data_collection=true, third_party_sharing=true — policy admits collection/sharing but not for this extension.
- no_developer_name store developer_name is empty string; no 'Offered by' entity visible to users.
- low_rating store Rating 3.4 across 60K installs; no specific red-flag review matches but dissatisfaction level is notable.
- verified_publisher store Extension carries verified_publisher=true badge, providing partial accountability signal.
- empty_js_surface crx js_file_count=0, code_findings_raw empty, obfuscation_score=0.0; extension has no JS to analyze.
- threat_intel_clean api bad_host_hits=[], monetization_hits=[], affiliate_hits=[], developer domain resolves, not throwaway.
Permissions Breakdown
- chrome_settings_overrides.search_provider medium Sets extension as default search provider; redirects all searches to findmypicsearches.com, a monetization vector.
Pillar Scores
Permissions3.00
Reputation5.50
Network0.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 09:09
Listing SHA
ae8131efb757…
Force block
— not fired
Score recovered
no
Elapsed
—