Is Pure Planet Earth safe?

Medium risk

Pure Planet Earth sets itself as your default search engine and stamps every search you make with a persistent tracking ID.

On install, the extension generates a random 32-character ID and stores it locally, then sends it to planetearthpure.com and registers it again as an uninstall beacon. Because the extension makes itself the browser's default search provider, every search query is silently rewritten to append this same ID before it is sent to planetearthpure.com, letting the vendor tie all of a user's searches to one durable identifier across sessions.

wardj4786v1.0.4Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Pure Planet Earth tags every search you type with a permanent tracking ID

Pure Planet Earth generates a permanent ID on install, beacons it to its own server, then uses a runtime redirect rule to attach that same ID to every search you type before your query reaches its server.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-359
Source
Dynamic sandbox
What actually happens
You did this

You install Pure Planet Earth and accept Chrome's prompt to make it your default search engine.

The extension did this

The extension creates a permanent 32-character random ID, saves it, and sends it to the vendor's own server.

It also registers the same ID with Chrome's uninstall-reporting API and installs a rule that attaches this ID to every search you make afterward.

Where your permanent ID shows up
  • Install beacon
    https://planetearthpure.com/start?session=24owjaxpi5wb3jpkw8hwiskuaju6juiv

    Sent once, right after install, to the vendor's own server.

  • Every search you type
    https://planetearthpure.com/search?q=weather+tomorrow&session=24owjaxpi5wb3jpkw8hwiskuaju6juiv

    Appended to your search query before it reaches the vendor's server, tying that search to your permanent ID.

  • Uninstall beacon
    https://planetearthpure.com/uninstall?session=24owjaxpi5wb3jpkw8hwiskuaju6juiv

    Sent if you remove the extension, confirming to the vendor which ID stopped being active.

Captured request
GEThttps://planetearthpure.com/search?q=canary_test_BIRD_12345&session=24owjaxpi5wb3jpkw8hwiskuaju6juiv

Observed during dynamic analysis: this is a redirect the extension's own rule injects on the way out. The vendor's server then issues a second redirect that forwards the bare, session-stripped query on to bing.com, so Bing returns the results while only the vendor's own server sees the session-tagged version.

The code that does this

The runtime rule that tags every search, installed outside the extension's static rules.json

Readable version

What the code above does, step by step

// 1. Read or create a permanent 32-char ID and store it.// 2. Register that ID as the uninstall-beacon payload.// 3. Wipe any existing declarativeNetRequest rules.// 4. Add a fresh runtime rule: any navigation whose URL contains//    'planetearthpure.com/search' gets '&session=<id>' appended//    to its query string before the request leaves the browser.
Where a tagged search ends up
    • planetearthpure.com

    The vendor's own domain: the extension's default search engine and the destination for the install, per-search, and uninstall beacons carrying your permanent session ID.

    • bing.com

    After the vendor's server logs your session-tagged query, it forwards the bare, session-stripped query here to fetch your actual search results.

Check if you're affected

Reads the extension's live storage and declarativeNetRequest rules to confirm the session ID and the redirect rule that tags your searches.

Requires
  • Chrome
  • Developer mode enabled in chrome://extensions
detect_session_redirect.js · js
// Run in the extension's own service-worker console.// chrome://extensions -> enable Developer mode -> Pure Planet Earth -> "service worker"chrome.storage.local.get(['session'], (settings) => {  console.log('Persistent session ID:', settings.session);});chrome.declarativeNetRequest.getDynamicRules((rules) => {  console.log('Active dynamic redirect rules:', JSON.stringify(rules, null, 2));});
How to run it
  1. 1Open chrome://extensions, enable Developer mode.
  2. 2Under Pure Planet Earth, click "service worker".
  3. 3Paste the script, press Enter.
  4. 4Match the logged ID to the session= value in your searches.

What it can do

Permissions this extension asks for, as declared in version 1.0.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on planetearthpure.com

    *://planetearthpure.com/*

  • Store data in your browser

    storage

  • Block and redirect the requests your browser makes

    declarativeNetRequest

Where it sends data

Destinations our analysis observed Pure Planet Earth contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • planetearthpure.com

    Pure Planet Earth sends data to planetearthpure.com. No other extension we have analysed sends data here.

Updated 30 September 2026llflfgnpglhgnbmfebokdfladhdhchoh