Is Pure Planet Earth safe?
Pure Planet Earth sets itself as your default search engine and stamps every search you make with a persistent tracking ID.
On install, the extension generates a random 32-character ID and stores it locally, then sends it to planetearthpure.com and registers it again as an uninstall beacon. Because the extension makes itself the browser's default search provider, every search query is silently rewritten to append this same ID before it is sent to planetearthpure.com, letting the vendor tie all of a user's searches to one durable identifier across sessions.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Pure Planet Earth tags every search you type with a permanent tracking ID
Pure Planet Earth generates a permanent ID on install, beacons it to its own server, then uses a runtime redirect rule to attach that same ID to every search you type before your query reaches its server.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-359
- Source
- Dynamic sandbox
You install Pure Planet Earth and accept Chrome's prompt to make it your default search engine.
The extension creates a permanent 32-character random ID, saves it, and sends it to the vendor's own server.
It also registers the same ID with Chrome's uninstall-reporting API and installs a rule that attaches this ID to every search you make afterward.
- Install beaconhttps://planetearthpure.com/start?session=24owjaxpi5wb3jpkw8hwiskuaju6juiv
Sent once, right after install, to the vendor's own server.
- Every search you typehttps://planetearthpure.com/search?q=weather+tomorrow&session=24owjaxpi5wb3jpkw8hwiskuaju6juiv
Appended to your search query before it reaches the vendor's server, tying that search to your permanent ID.
- Uninstall beaconhttps://planetearthpure.com/uninstall?session=24owjaxpi5wb3jpkw8hwiskuaju6juiv
Sent if you remove the extension, confirming to the vendor which ID stopped being active.
Observed during dynamic analysis: this is a redirect the extension's own rule injects on the way out. The vendor's server then issues a second redirect that forwards the bare, session-stripped query on to bing.com, so Bing returns the results while only the vendor's own server sees the session-tagged version.
The runtime rule that tags every search, installed outside the extension's static rules.json
What the code above does, step by step
// 1. Read or create a permanent 32-char ID and store it.// 2. Register that ID as the uninstall-beacon payload.// 3. Wipe any existing declarativeNetRequest rules.// 4. Add a fresh runtime rule: any navigation whose URL contains// 'planetearthpure.com/search' gets '&session=<id>' appended// to its query string before the request leaves the browser.- planetearthpure.com
The vendor's own domain: the extension's default search engine and the destination for the install, per-search, and uninstall beacons carrying your permanent session ID.
- bing.com
After the vendor's server logs your session-tagged query, it forwards the bare, session-stripped query here to fetch your actual search results.
Reads the extension's live storage and declarativeNetRequest rules to confirm the session ID and the redirect rule that tags your searches.
- Chrome
- Developer mode enabled in chrome://extensions
// Run in the extension's own service-worker console.// chrome://extensions -> enable Developer mode -> Pure Planet Earth -> "service worker"chrome.storage.local.get(['session'], (settings) => { console.log('Persistent session ID:', settings.session);});chrome.declarativeNetRequest.getDynamicRules((rules) => { console.log('Active dynamic redirect rules:', JSON.stringify(rules, null, 2));});- 1Open chrome://extensions, enable Developer mode.
- 2Under Pure Planet Earth, click "service worker".
- 3Paste the script, press Enter.
- 4Match the logged ID to the session= value in your searches.
What it can do
Permissions this extension asks for, as declared in version 1.0.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on planetearthpure.com
*://planetearthpure.com/*
Store data in your browser
storage
Block and redirect the requests your browser makes
declarativeNetRequest
Where it sends data
Destinations our analysis observed Pure Planet Earth contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- planetearthpure.com
Pure Planet Earth sends data to planetearthpure.com. No other extension we have analysed sends data here.