Is Littsearch - NewTab safe?

Medium risk

Littsearch is medium risk. Each new-tab search sends your term, provider, and a persistent install ID to littsearch.com before forwarding you to the engine. The ID derives from chrome.runtime.id, stable for the install's life, letting it build a search history.

littsearchv1.0.4Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Search Queries Routed Through littsearch.com With Persistent Install ID

Each new-tab search sends your term, provider, and a persistent install ID to littsearch.com before forwarding you to the engine.

The ID derives from chrome.runtime.id, stable for the install's life, letting it build a search history.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You enter a search query in the new-tab search bar and submit the form.

The extension did this

The extension navigates to littsearch.com/serp.php, appending your query, provider, version, and an install ID from chrome.runtime.id.

The intermediary request is not visible in the browser address bar until littsearch.com processes it and redirects.

02EvidenceFIELD TABLE
Parameters sent to littsearch.com on every search
FieldValueWhy it matters
Install identifier
gehgcngjjbengkehfgnciflogmoifiieA stable ID tied to your install, unchanged between sessions, letting littsearch.com link searches over time.
Search query
flights to amsterdam next weekThe exact text you typed into the search bar.
Chosen search provider
google.comThe engine you selected (Bing, Google, Yahoo, or DuckDuckGo), revealing your preferences.
Extension version
1.0.4The installed version of the extension, sent on every request.
03EvidenceCODE COMPARE
The code that does this

Search submission handler in provider.js

What it actually does
// On every search, all four parameters are assembled and the tab is navigated
// to littsearch.com BEFORE reaching the user's chosen engine.
// chrome.runtime.id is the stable per-install extension ID — it persists
// across browser restarts and sessions for the lifetime of the installation.
document.querySelector('form.search').addEventListener('submit', function (el) {
    const form = new FormData(el.target);
    const provider = form.get("provider");       // e.g. "google.com"
    const searchterm = form.get("searchterm");   // the raw query text
    el.preventDefault();
    var manifestData = chrome.runtime.getManifest();
    // Persistent install ID included on every request:
    let searchurl = "https://littsearch.com/serp.php"
        + "?v=" + encodeURIComponent(manifestData.version)  // "1.0.4"
        + "&id=" + encodeURIComponent(chrome.runtime.id)    // stable install ID
        + "&q=" + encodeURIComponent(searchterm)            // raw query
        + "&provider=" + encodeURIComponent(provider);      // chosen engine
    window.location.href = searchurl;  // navigate tab through littsearch.com
});
04EvidenceTHIRD PARTY LIST
Destination receiving search data
  • littsearch.com

    Operator-controlled intermediary that receives every search query, the persistent install identifier, and the chosen provider before redirecting to the actual search engine.

05EvidenceARTIFACT
Reproduce it yourself

Constructs the exact URL that the extension sends to littsearch.com for a given search query, so you can observe the parameters without installing the extension.

RequiresNode.js 18+ or any modern browser console
reproduce_littsearch_routing.js · js
// Reproduces the URL the extension sends to littsearch.com.
// Run in Node.js or any browser console.
// Replace INSTALL_ID with the runtime ID of the installed extension
// (visible at chrome://extensions when developer mode is on).

const INSTALL_ID = 'gehgcngjjbengkehfgnciflogmoifiie'; // example
const VERSION = '1.0.4';
const QUERY = 'flights to amsterdam next week';        // your test query
const PROVIDER = 'google.com';

const url = 'https://littsearch.com/serp.php'
  + '?v=' + encodeURIComponent(VERSION)
  + '&id=' + encodeURIComponent(INSTALL_ID)
  + '&q=' + encodeURIComponent(QUERY)
  + '&provider=' + encodeURIComponent(PROVIDER);

console.log('URL sent to littsearch.com:');
console.log(url);
// Open this URL in a browser to observe what littsearch.com returns
// before it forwards you to the chosen search engine.
How to run it
  1. 1
    Copy the script.
  2. 2
    Open a console.
  3. 3
    Set INSTALL_ID to the ID in chrome://extensions.
  4. 4
    Set QUERY to a search term.
  5. 5
    Run and open the logged URL.

What it can do

Permissions this extension asks for, as declared in version 1.0.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

Updated 30 September 2026gehgcngjjbengkehfgnciflogmoifiie