Is Quick Search Tool safe?

High risk

Quick Search Tool is high risk. Every search via Quick Search Tool's built-in provider goes to query.quicksearchtool.com with tracking parameters: install UUID, install date, and a hardcoded source ID. Two searches shared the same UID, tying your history together.

quicksearchtool.comv1.3Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Search Queries Tagged with Persistent Tracking ID on Every Use

Every search via Quick Search Tool's built-in provider goes to query.quicksearchtool.com with tracking parameters: install UUID, install date, and a hardcoded source ID.

Two searches shared the same UID, tying your history together.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You type a search query into the address bar while Quick Search Tool is installed.

The extension did this

The extension appends your persistent UUID, install date, and source code to the search URL before it leaves your browser.

This happens on every search with no opt-out or disclosure in the extension UI.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://query.quicksearchtool.com/s?query=<planted-marker>&source=nocache&uid=1fda50f2-f581-da67-1737-7158dc72a231&ap=appfocus1&uc=20260415&i_id=quicksearchtool_1.3&cid=edpknbmdcbpmffcmfafkchpkeloemafh
03EvidenceFIELD TABLE
Tracking parameters appended to every search request:
FieldValueWhy it matters
Your persistent user ID
1fda50f2-f581-da67-1737-7158dc72a231A UUID assigned to your browser at install. Appears in every search request, linking all your searches, even across restarts.
Install source
nocacheA code indicating how the extension was acquired (e.g. which distribution partner referred you). The same value is sent with every search.
Install date
20260415The date you installed the extension, as YYYYMMDD. Combined with the UUID, lets the server compute how long you've been a user.
Traffic source / AP code
appfocus1A campaign or traffic-source code set at install time. Used to attribute the install to a distribution partner.
Extension version + vertical
quicksearchtool_1.3The extension's ID string and version number, identifying which build you are running.
Chrome extension ID
edpknbmdcbpmffcmfafkchpkeloemafhYour browser's unique identifier for this extension installation.
04EvidenceCODE COMPARE
The code that does this

declarativeNetRequest rule appending tracking parameters to every search (background.js:11-40)

What it actually does
// Reads the 4 tracking values stored in chrome.storage.sync at install time,
// then registers a declarativeNetRequest redirect rule (id:1) that fires on
// every main_frame navigation to query.quicksearchtool.com/s.
//
// The rule uses a queryTransform to ADD these params to every search URL:
// source — install-source code (e.g. 'nocache', 'web_store')
// uid — persistent UUID assigned at install (your identity token)
// ap — traffic/campaign source code (e.g. 'appfocus1')
// uc — install date as YYYYMMDD (e.g. '20260415')
// i_id — extension vertical + version (e.g. 'quicksearchtool_1.3')
// cid — Chrome extension ID (unique per browser install)
//
// setSearchUrl() is called once at install/update in the onInstalled listener,
// so the rule is always active for the lifetime of the extension.
const setSearchUrl = async () => {
 const { src: installSource, uid: persistentUUID, ap: trafficSource, uc: installDate } = await chrome.storage.sync.get(['src','uid','ap','uc']);
 await chrome.declarativeNetRequest.updateDynamicRules({
 removeRuleIds: [1], // remove old rule first (idempotent)
 addRules: [{
 id: 1,
 priority: 1,
 action: {
 type: 'redirect',
 redirect: {
 transform: {
 queryTransform: {
 addOrReplaceParams: [
 { key: 'source', value: installSource || 'nocache' },
 { key: 'uid', value: persistentUUID || '' }, // ← your identity
 { key: 'ap', value: trafficSource || 'nocache' },
 { key: 'uc', value: installDate || '17000101' },
 { key: 'i_id', value: 'quicksearchtool_' + extensionVersion },
 { key: 'cid', value: chrome.runtime.id },
 ]
 }
 }
 }
 },
 condition: {
 urlFilter: 'query.quicksearchtool.com/s',
 resourceTypes: ['main_frame']
 }
 }]
 });
};
05EvidenceSTORAGE DUMP
What's stored on your device

Written to synced storage at install, read before every search. Via chrome.storage.sync, they follow you across signed-in devices.

Locationchrome.storage.sync (set at install, read on every search)
Contents (JSON)
{
  "ap": "appfocus1",
  "uc": "20260415",
  "src": "nocache",
  "uid": "1fda50f2-f581-da67-1737-7158dc72a231"
}
06EvidenceTHIRD PARTY LIST
Where your search data is sent:
  • query.quicksearchtool.com

    Receives every search query along with the persistent UID and attribution parameters. This is the overridden default search engine endpoint.

  • log.quicksearchtool.com

    Receives lifecycle events (install, update, sync) with the same uid and attribution parameters via the sendLog() function in background.js.

07EvidenceARTIFACT
Reproduce it yourself

Run this in the Chrome DevTools console (on any page) while Quick Search Tool is installed. It reads the tracking values from chrome.storage.sync and reconstructs the exact URL that will be used for your next search, so you can see your persistent UID and confirm it matches what gets sent.

RequiresChrome with Quick Search Tool installedDevTools access (F12)
qst-tracking-checker.js · js
// qst-tracking-checker.js
// Run in Chrome DevTools console while Quick Search Tool is installed.
// Reads the stored tracking values and shows the URL your next search will use.

(async () => {
 const data = await chrome.storage.sync.get(['src', 'uid', 'ap', 'uc']);
 console.log('Stored tracking values:', data);

 const extensionVersion = chrome.runtime.getManifest().version;
 const extensionId = chrome.runtime.id;
 const testQuery = 'hello world';

 const url = new URL('https://query.quicksearchtool.com/s');
 url.searchParams.set('query', testQuery);
 url.searchParams.set('source', data.src || 'nocache');
 url.searchParams.set('uid', data.uid || '');
 url.searchParams.set('ap', data.ap || 'nocache');
 url.searchParams.set('uc', data.uc || '17000101');
 url.searchParams.set('i_id', 'quicksearchtool_' + extensionVersion);
 url.searchParams.set('cid', extensionId);

 console.log('Your next search URL (with tracking):');
 console.log(url.toString());
 console.log('');
 console.log('Your persistent UID:', data.uid);
 console.log('This UID will appear in every search request from this browser.');
})();
How to run it
  1. 1
    Install Quick Search Tool.
  2. 2
    Open a tab, press F12 for DevTools, switch to Console.
  3. 3
    Paste this script, press Enter; it prints your stored UID and the URL your next search will use.
  4. 4
    Search and compare the UID shown; they'll match.

What it can do

Permissions this extension asks for, as declared in version 1.3. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on quicksearchtool.com

    *://*.quicksearchtool.com/*

  • Read and change your data on query.quicksearchtool.com

    *://query.quicksearchtool.com/*

  • See the address and title of every tab you have open

    tabs

  • Store data in your browser

    storage

  • Block and redirect the requests your browser makes

    declarativeNetRequest

  • Read and change cookies, including the ones that keep you signed in

    cookies

Updated 30 September 2026keadechokmcohlcampccppbjjeabghcd