Is Predator Search safe?
Predator Search is medium risk. When you search from the address bar, the extension routes the query through predatorwallpaper.com and appends a tracking token that stays the same across sessions, letting the operator build a permanent record of your searches.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Every search query sent to predatorwallpaper.com with a persistent tracking ID
When you search from the address bar, the extension routes the query through predatorwallpaper.com and appends a tracking token that stays the same across sessions, letting the operator build a permanent record of your searches.
You type a search query into the browser address bar.
This applies to every search regardless of content.
The extension sends the query to predatorwallpaper.com tagged with a permanent session token.
The token is the same value across every browser session, allowing the operator to correlate all your searches over time.
A 32-character token stored on first run. It is never cleared or rotated, so it permanently identifies your browser to the search service.
chrome.storage.local key 'session'{ "session": "k7m2x9nq4a8bc3ht0e5fvr6ujwyps1dz" }| Field | Value | Why it matters | |
|---|---|---|---|
Your search query | cheap flights london new york | The exact words you typed into the address bar. | |
Persistent browser token | k7m2x9nq4a8bc3ht0e5fvr6ujwyps1dz | A fixed identifier that lets the operator link every search back to your browser across all sessions. |
Session token generation and DNR rule injection (bgrd.js)
chrome.storage.local.get(["session"], settings => {
let session;
if (settings.session) {
session = settings.session;
} else {
session = [...Array(32)].map(() => (~~(Math.random() * 36)).toString(36)).join("");
chrome.storage.local.set({session: session}, () => {
fetch(`https://predatorwallpaper.com/start?session=${session}`, {
mode: "no-cors",
cache: "no-cache",
credentials: "same-origin",
redirect: "follow",
referrerPolicy: "no-referrer"
}).then();
});
}
chrome.runtime.setUninstallURL(`https://predatorwallpaper.com/uninstall?session=${session}`);
chrome.declarativeNetRequest.getDynamicRules(rules => {
chrome.declarativeNetRequest.updateDynamicRules({
removeRuleIds: rules.map(rule => rule.id)
}, () => {
chrome.declarativeNetRequest.updateDynamicRules({
addRules: [{
id: 10,
action: {
type: "redirect",
redirect: {
transform: {
queryTransform: {
addOrReplaceParams: [{
key: "session",
value: session
}]
}
}
}
},
condition: {urlFilter: "predatorwallpaper.com/search", resourceTypes: ["main_frame"]}
}]
}).then();
});
});
});- predatorwallpaper.com
Receives every search query paired with a persistent browser token. Also receives an install beacon (via /start) and is set as the uninstall URL (/uninstall).
What it can do
Permissions this extension asks for, as declared in version 1.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on predatorwallpaper.com
*://predatorwallpaper.com/*
Store data in your browser
storage
Block and redirect the requests your browser makes
declarativeNetRequest