TurtleWave Search
pogifpdbhckbplbmkbcanocicellkghc
Risk Score
3.37
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing (pillar score 10).
- Developer email is free-webmail (gmail) with no developer name listed; identity unverifiable.
- Search engine override redirects all searches to turtlewave.dev, an unverified third-party domain.
- Verified-publisher badge paired with anonymous free-webmail identity and unrelated generic privacy policy is suspicious.
- Only 6 installs with verified-publisher status is anomalous; may be a test/staging extension with real capability.
Evidence
- search_provider_override manifest chrome_settings_overrides.search_provider sets default to https://search.turtlewave.dev/search — unverified third-party domain.
- generic_privacy_policy store Privacy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — scores 10.0.
- free_webmail_dev_no_name store Developer email yourmomscottcontact@gmail.com is free-webmail; developer_name is empty — identity unverifiable.
- verified_publisher_anomaly store verified_publisher=true but developer_name blank, free-webmail email, 6 installs — verification value questionable.
- no_code_surface crx js_file_count=0, code_findings_raw=[], obfuscation_score=0.0 — extension has no JS; risk is purely the search override.
- cve_clean crx cve_findings_raw is empty; no vulnerable libraries detected.
- no_bad_hosts api threat_intel bad_host_hits, monetization_hits, and affiliate_hits all empty.
- low_install_count store Only 6 installs; blast radius minimal today but extension is published and accessible.
Permissions Breakdown
- chrome_settings_overrides.search_provider medium Overrides default search engine to turtlewave.dev; medium-tier override per rubric rule (a).
Pillar Scores
Permissions1.00
Reputation7.50
Network0.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:32
Listing SHA
eab1abfa4802…
Force block
— not fired
Score recovered
no
Elapsed
—