Is Littsearch - NewTab safe?
Littsearch is medium risk. Each new-tab search sends your term, provider, and a persistent install ID to littsearch.com before forwarding you to the engine. The ID derives from chrome.runtime.id, stable for the install's life, letting it build a search history.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Search Queries Routed Through littsearch.com With Persistent Install ID
Each new-tab search sends your term, provider, and a persistent install ID to littsearch.com before forwarding you to the engine.
The ID derives from chrome.runtime.id, stable for the install's life, letting it build a search history.
You enter a search query in the new-tab search bar and submit the form.
The extension navigates to littsearch.com/serp.php, appending your query, provider, version, and an install ID from chrome.runtime.id.
The intermediary request is not visible in the browser address bar until littsearch.com processes it and redirects.
| Field | Value | Why it matters | |
|---|---|---|---|
Install identifier | gehgcngjjbengkehfgnciflogmoifiie | A stable ID tied to your install, unchanged between sessions, letting littsearch.com link searches over time. | |
Search query | flights to amsterdam next week | The exact text you typed into the search bar. | |
Chosen search provider | google.com | The engine you selected (Bing, Google, Yahoo, or DuckDuckGo), revealing your preferences. | |
Extension version | 1.0.4 | The installed version of the extension, sent on every request. |
Search submission handler in provider.js
// On every search, all four parameters are assembled and the tab is navigated
// to littsearch.com BEFORE reaching the user's chosen engine.
// chrome.runtime.id is the stable per-install extension ID — it persists
// across browser restarts and sessions for the lifetime of the installation.
document.querySelector('form.search').addEventListener('submit', function (el) {
const form = new FormData(el.target);
const provider = form.get("provider"); // e.g. "google.com"
const searchterm = form.get("searchterm"); // the raw query text
el.preventDefault();
var manifestData = chrome.runtime.getManifest();
// Persistent install ID included on every request:
let searchurl = "https://littsearch.com/serp.php"
+ "?v=" + encodeURIComponent(manifestData.version) // "1.0.4"
+ "&id=" + encodeURIComponent(chrome.runtime.id) // stable install ID
+ "&q=" + encodeURIComponent(searchterm) // raw query
+ "&provider=" + encodeURIComponent(provider); // chosen engine
window.location.href = searchurl; // navigate tab through littsearch.com
});- littsearch.com
Operator-controlled intermediary that receives every search query, the persistent install identifier, and the chosen provider before redirecting to the actual search engine.
Constructs the exact URL that the extension sends to littsearch.com for a given search query, so you can observe the parameters without installing the extension.
// Reproduces the URL the extension sends to littsearch.com.
// Run in Node.js or any browser console.
// Replace INSTALL_ID with the runtime ID of the installed extension
// (visible at chrome://extensions when developer mode is on).
const INSTALL_ID = 'gehgcngjjbengkehfgnciflogmoifiie'; // example
const VERSION = '1.0.4';
const QUERY = 'flights to amsterdam next week'; // your test query
const PROVIDER = 'google.com';
const url = 'https://littsearch.com/serp.php'
+ '?v=' + encodeURIComponent(VERSION)
+ '&id=' + encodeURIComponent(INSTALL_ID)
+ '&q=' + encodeURIComponent(QUERY)
+ '&provider=' + encodeURIComponent(PROVIDER);
console.log('URL sent to littsearch.com:');
console.log(url);
// Open this URL in a browser to observe what littsearch.com returns
// before it forwards you to the chosen search engine.- 1Copy the script.
- 2Open a console.
- 3Set INSTALL_ID to the ID in chrome://extensions.
- 4Set QUERY to a search term.
- 5Run and open the logged URL.
What it can do
Permissions this extension asks for, as declared in version 1.0.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Store data in your browser
storage