Is Play Games safe?
Play Games sets itself as the browser's default search engine on install and sends every omnibox search to onlinegamessearch.com.
The extension declares a manifest search provider override with is_default set to true, so on install it replaces the browser's chosen default search engine without a runtime permission prompt. Every non-URL query typed into the address bar – not just game-related searches – is then sent to onlinegamessearch.com instead of the user's normal search provider. The new provider's display name is left blank, which can make the change harder to notice or undo in the browser's search-engine settings.
Who publishes itOnline Search Tool - 3 other listings from the same operator, 1 of them carrying a finding
Online Search Tool - 3 other listings from the same operator, 1 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
3 other listings published from this account, 64k+ users between them. 1 of them carries a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Play Games becomes your default search engine, off-site for every query
manifest.json sets onlinegamessearch.com as the default search engine on install.
Once accepted, every address-bar query you type, not only game searches, goes to that domain instead of your prior search engine.
You accept Chrome's one-time prompt asking whether Play Games can become your default search engine.
This native Chrome prompt appears once, right after install.
Every plain-text query you later type into the address bar is sent to onlinegamessearch.com instead of your previous default search engine.
This covers all address-bar searches, not only the game-related terms the extension's popup describes.
| Field | Value | Why it matters | |
|---|---|---|---|
Provider name | "" (empty string) | The name Chrome shows for this provider in its settings page. | |
Set as default | true | Tells Chrome to make this provider the browser's default search engine on install. | |
Search destination | https://onlinegamessearch.com/auto-suggest/search.php?q=weather+forecast+tomorrow | Where a typed query goes when you press Enter in the address bar. | |
Autosuggest destination | https://onlinegamessearch.com/auto-suggest/?q=weather+fore | Where partial text goes as you type, before you press Enter. | |
Settings keyword | games search | The internal identifier this entry uses in chrome://settings/searchEngines. |
manifest.json, unminified: the block that performs the takeover
"chrome_settings_overrides": {
"search_provider": {
"name": "",
"keyword": "games search",
"search_url": "https://onlinegamessearch.com/auto-suggest/search.php?q={searchTerms}",
"suggest_url": "https://onlinegamessearch.com/auto-suggest/?q={searchTerms}",
"favicon_url": "https://onlinegamessearch.com/favicon.ico",
"encoding": "UTF-8",
"is_default": true
}
}- onlinegamessearch.com
Receives the full text of every default-bar search and every autosuggest keystroke, and returns the search results and suggestions shown to you.
Scans an unpacked extension's manifest.json for a default-search-engine override and prints what it would replace, so you can spot this pattern in other extensions.
#!/usr/bin/env node
// check_search_override.js
// Usage: node check_search_override.js /path/to/unpacked/manifest.json
const fs = require('fs');
const manifestPath = process.argv[2];
if (!manifestPath) {
console.error('Usage: node check_search_override.js <path-to-manifest.json>');
process.exit(1);
}
const raw = fs.readFileSync(manifestPath, 'utf8');
const manifest = JSON.parse(raw);
const override = manifest.chrome_settings_overrides && manifest.chrome_settings_overrides.search_provider;
if (!override) {
console.log('No chrome_settings_overrides.search_provider block found. This extension does not declare a default search engine override.');
process.exit(0);
}
console.log('Default search engine override found:');
console.log(' Provider name :', JSON.stringify(override.name));
console.log(' Sets itself default :', override.is_default === true);
console.log(' Search destination :', override.search_url);
console.log(' Autosuggest dest. :', override.suggest_url);
console.log(' Settings keyword :', override.keyword);
if (override.name === '' || override.name === undefined) {
console.log('\nWarning: the provider name is blank. It may render as an empty row in chrome://settings/searchEngines, making it easy to miss.');
}
if (override.is_default === true) {
console.log('\nWarning: is_default is true. Accepting this extension\'s one-time install prompt makes it the browser default, so every address-bar query is routed to the search_url domain above.');
}
- 1Unpack the .crx or unzip the extension you want to check.
- 2Run: node check_search_override.js /path/to/unpacked/manifest.json
- 3Read the printed search_url and suggest_url before deciding whether to allow the extension.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
Where it sends data
Destinations our analysis observed Play Games contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- onlinegamessearch.com
Play Games sends data to onlinegamessearch.com. No other extension we have analysed sends data here.