Is My Focal Find safe?

Medium risk

My Focal Find sets itself as the default search engine and tags every search you type with a persistent per-install ID.

My Focal Find changes the browser's default search provider to myfocalfind.com. On install it generates a random 32-character ID, stores it locally, and sends it to the extension's server; from then on that same ID is silently appended to every search query typed into the address bar, and sent once more if the extension is uninstalled.

reedd6868v1.0.2Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

My Focal Find tags every search you make with a persistent tracking ID

Code analysis shows the extension creates a random per-install ID, then installs a network rule appending it to every search sent through its default search engine, plus matching install/uninstall beacons.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You type a search into the browser's address bar.

My Focal Find sets itself as the default search engine, so the address bar sends the search to myfocalfind.com.

The extension did this

A network rule the extension installed rewrites the request to add a fixed tracking ID before it leaves your browser.

The same ID was created once at install and is reused for every search from then on.

02EvidenceCODE COMPARE
The code that does this

Session ID generation, install beacon, and search-rewrite rule

What it actually does
// Extension ships this code unminified already; layout unchanged.
// Effect, in order:
// 1. Read (or create once) a persistent 32-char random session ID from local storage.
// 2. On first creation, send that ID to myfocalfind.com/start (install beacon).
// 3. Register the same ID as the value sent to myfocalfind.com/uninstall (uninstall beacon).
// 4. Install a declarativeNetRequest rule that rewrites any request matching
//    'myfocalfind.com/search' to append '&session=<the same ID>' to the query string.
// Because manifest.json sets myfocalfind.com as the default search_provider,
// step 4 fires on every omnibox search made while it remains the default engine.
03EvidenceFIELD TABLE
Fields attached to each rewritten search request
FieldValueWhy it matters
Persistent install ID
session=k3j9m2p7q1r5t8v0w2x4y6z8a1b3c5d7A fixed ID for your install that stays the same across every search, letting the same searches be tied together over time.
Search term
q=best noise cancelling headphonesThe text you typed into the address bar, sent as part of choosing myfocalfind.com as your search engine.
04EvidenceTHIRD PARTY LIST
Destination for the tracking ID
  • myfocalfind.com

    Receives the install beacon, every rewritten search carrying the same persistent ID, and the uninstall beacon; also the search engine itself.

05EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

What it can do

Permissions this extension asks for, as declared in version 1.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on myfocalfind.com

    *://myfocalfind.com/*

  • Store data in your browser

    storage

  • Block and redirect the requests your browser makes

    declarativeNetRequest

Where it sends data

Destinations our analysis observed My Focal Find contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • myfocalfind.com

    My Focal Find sends data to myfocalfind.com. No other extension we have analysed sends data here.

Updated 30 September 2026eeejfmalgedffijdepcdmgemfnadjefe