Is MapQuest Search safe?
MapQuest Search is high risk. Every address-bar search routes through mapquestdrivingdirections.org before reaching Yahoo's infospace search. A campaign ID matching the install ID and an install-date stamp let the operator attribute searches and link history.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Search queries routed through monetization funnel with per-install tracking
Every address-bar search routes through mapquestdrivingdirections.org before reaching Yahoo's infospace search.
A campaign ID matching the install ID and an install-date stamp let the operator attribute searches and link history.
You type a search query into the browser address bar and press Enter.
The extension has replaced the default search engine via chrome_settings_overrides.search_provider, so all omnibox searches are directed through its endpoint.
The extension injects your unique install ID and the date you first installed it into every search request before it leaves your browser.
A declarativeNetRequest dynamic rule appends campaignid=<extension-runtime-id> and installdate=<YYYYMMDD> to each request matching mapquestdrivingdirections.org/admin-search/public/link, then the operator's server forwards the query to Yahoo infospace.
| Field | Value | Why it matters | |
|---|---|---|---|
Install ID (campaignid) | onpkagahfdnlknakhgnegpipmhkodnlm | A fixed identifier tied to your browser install. Lets the operator link all your searches across sessions and days, even without login. | |
Install date (installdate) | 20240315 | The date you first installed the extension, as YYYYMMDD. Stored locally and attached to every search so the operator knows your tenure. | |
Search query (q / p) | cheap flights london to new york | The words you typed into the address bar. Delivered first to the operator's domain and then forwarded to Yahoo's infospace service. |
DNR rule injects tracking parameters on every search, background.js
const extensionDomain = 'mapquestdrivingdirections.org', campaignid = chrome.runtime.id;
const getTracking = () => new Promise(r => chrome.storage.sync.get(r));
const setUpSearchUrl = async () => {
const { installdate } = await getTracking();
await chrome.declarativeNetRequest.updateDynamicRules({
removeRuleIds: [1],
addRules: [
{
id: 1,
priority: 1,
action: {
type: "redirect",
redirect: {
transform: {
queryTransform: {
addOrReplaceParams: [
{ key: "campaignid", value: campaignid },
{ key: "installdate", value: installdate || new Date().toISOString().split('T')[0].replace(/-/g, '') },
]
}
}
}
},
condition: { urlFilter: "mapquestdrivingdirections.org/admin-search/public/link", resourceTypes: ["main_frame"] }
}
]
});
};- mapquestdrivingdirections.org
Operator-controlled intermediary. Receives every search query plus campaignid and installdate tracking parameters. Redirects requests to Yahoo infospace on the server side.
- uk.search.yahoo.com
Yahoo infospace search results endpoint. Final destination for queries; affiliate parameters (hspart=infospace, hsimp=yhs-090) indicate the operator earns per-search revenue.
What it can do
Permissions this extension asks for, as declared in version 1.6. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on mapquestdrivingdirections.org
*://mapquestdrivingdirections.org/*
Store data in your browser
storage
Block and redirect the requests your browser makes
declarativeNetRequest