Is Movie Finder safe?

High risk

Movie Finder is high risk. On install, Movie Finder's worker sets two persistent cookies on moviefindersearch.com, also used for search, homepage, uninstall. 'use_ac'/'services' are Secure, SameSite=None, 365-day; 'services' is a base64 copy of your streaming picks.…

Movie Finderv3.0.1Chrome Web Store
75Risk
Who publishes it

Movie Finder - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Movie Finder

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Movie Finder writes 1-year tracking cookies to its own domain on install

On install, Movie Finder's worker sets two persistent cookies on moviefindersearch.com, also used for search, homepage, uninstall. 'use_ac'/'services' are Secure, SameSite=None, 365-day; 'services' is a base64 copy of your streaming picks.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click "Add to Chrome" to install Movie Finder.

The extension did this

The background service worker immediately writes two long-lived tracking cookies to moviefindersearch.com, before you've searched for anything.

Both cookies are Secure, SameSite=None, and set to expire 365 days later.

02EvidenceFIELD TABLE
Cookies written to .moviefindersearch.com
FieldValueWhy it matters
Autocomplete preference flag
use_ac=trueA persistent flag the site can read on every visit, tying that browser to moviefindersearch.com across sessions.
Streaming-service preferences
services=W3sicHJvdmlkZXIiOiJuZXRmbGl4Ii4uLg== (illustrative — the default list every install starts with; updates as you toggle services)An encoded copy of your selected movie/TV streaming services, decodable by anyone who reads the cookie (see below).
Default search engine choice
se=google (illustrative)Set later, when you change the default search engine inside the extension, written by the same cookie mechanism.
"Keep changes" dialog state
keep_changes=1 (illustrative)Records whether you dismissed the extension's settings-changed prompt, also readable by moviefindersearch.com.
03EvidenceOPAQUE REVEAL
Why you can't catch this in DevTools

The 'services' cookie looks like an opaque token in the cookie jar, but it's just JSON run through encodeURIComponent + btoa. Any page or tool that reads the cookie can reverse it in one line.

What's actually being sent
[
  {
    "provider": "netflix",
    "command": "@nf",
    "active": true,
    "title": "Netflix",
    "description": "One of the world’s largest TV shows and movies streaming platform."
  },
  {
    "provider": "amazonp",
    "command": "@am",
    "active": true,
    "title": "Amazon Prime",
    "description": "The movies streaming service developed by Amazon."
  },
  {
    "provider": "justwatch",
    "command": "@jw",
    "active": true,
    "title": "JustWatch",
    "description": "A movies and TV shows and podcast streaming platform."
  },
  {
    "provider": "imdb",
    "command": "@imdb",
    "active": true,
    "title": "IMDb",
    "description": "A movies and TV shows rating platform."
  },
  {
    "provider": "rotten",
    "command": "@rt",
    "active": true,
    "title": "Rotten Tomatoes",
    "description": "A movies and podcast rating platform."
  },
  {
    "provider": "reelgood",
    "command": "@rg",
    "active": false,
    "title": "Reelgood",
    "description": "The streaming service that brings movie, TV shows to one place."
  }
]
04EvidenceTHIRD PARTY LIST
Where the cookies are readable
  • moviefindersearch.com

    Receives the 'use_ac'/'services' cookies, and set its own 1-year, SameSite=None cookie during a test search, using the same partner ID (s=dkds) seen across the extension's URLs.

05EvidenceARTIFACT
Reproduce it yourself

Decodes the base64 'services' cookie value moviefindersearch.com receives back into readable JSON, reversing the extension's own encoding chain.

RequiresNode.js 12+
decode-services-cookie.js · js
// decode-services-cookie.js
// Reverses Movie Finder's own encoding chain for the 'services' cookie:
//   btoa(unescape(encodeURIComponent(JSON.stringify(data))))
// so you can read exactly what the cookie carries.

const raw = process.argv[2];

if (!raw) {
  console.error('Usage: node decode-services-cookie.js "<cookie value>"');
  process.exit(1);
}

const binary = Buffer.from(raw, 'base64').toString('binary');
const percentEncoded = escape(binary);
const json = decodeURIComponent(percentEncoded);

console.log(JSON.stringify(JSON.parse(json), null, 2));
How to run it
  1. 1
    Open DevTools > Application > Cookies on moviefindersearch.com after installing Movie Finder.
  2. 2
    Copy the value of the 'services' cookie.
  3. 3
    Run: node decode-services-cookie.js "<cookie value>"
SeverityLOW
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Uninstalling Movie Finder reports the affiliate partner ID to its vendor

Movie Finder registers an uninstall URL via chrome.runtime.setUninstallURL().

Uninstalling navigated Chrome to moviefindersearch.com/wim/uninstall with s=dkds and vert=movie, the same affiliate ID baked into the extension's other endpoints.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You uninstall Movie Finder.

The extension did this

Chrome automatically opens an affiliate-tagged URL on moviefindersearch.com that the extension registered when it was installed.

The request carries the same partner ID used throughout the extension's other vendor endpoints.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://www.moviefindersearch.com/wim/uninstall?s=dkds&vert=movie
HTTP 302, Chrome navigated to this URL as the extension's uninstall process completed.
03EvidenceFIELD TABLE
Fields in the uninstall request
FieldValueWhy it matters
Affiliate partner ID
s=dkdsIdentifies which distribution partner installed this copy, the same ID used in the extension's search, homepage, and help URLs.
Product vertical tag
vert=movieTells the vendor which product category (movies) this uninstall belongs to.
04EvidenceTHIRD PARTY LIST
Where the uninstall event goes
  • moviefindersearch.com

    Receives the uninstall notification tagged with the affiliate ID (s=dkds) and vertical (vert=movie), the same domain that received the extension's tracking cookies on install.

What it can do

Permissions this extension asks for, as declared in version 3.0.1. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on moviefindersearch.com

    *://*.moviefindersearch.com/*

  • Add items to the right-click menu

    contextMenus

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • Store data in your browser

    storage

Updated 30 September 2026jdakbaajckankfaadpapgnnlealoigaj