Is Search Switch safe?

Medium risk

Search Switch sets your default search engine to customserp.com instead of the Bing integration it advertises.

The extension's manifest registers itself as Chrome's default search provider and routes every address-bar search to customserp.com/search.php, sending the raw query as a URL parameter. Its own description claims it switches searches to Microsoft Bing, but no code in the extension ever queries or forwards results from bing.com. Every search term you type is instead sent to this unbranded third-party domain.

searchswitchlabv1.0.4Chrome Web Store
45Risk
Who publishes it

Sorrento LTD - no other listings under this identity

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
searchswitchlab
Declared legal entity
Sorrento LTD

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI FOUND

Search Switch reroutes your default search to an unbranded domain, not Bing

Search Switch tells the Chrome Web Store it switches your searches to Microsoft Bing, but its manifest sets an unbranded domain, customserp.com, as your default search engine, so every query typed in the address bar goes there instead.

01EvidenceCAUSE EFFECT
What actually happens
You did this

Types a search query into the Chrome address bar and presses enter.

The extension did this

Sends the full query to customserp.com instead of bing.com or the browser's prior default engine.

The extension's manifest registers itself as the active default search provider on install.

02EvidenceFIELD TABLE
What the listing promises vs what the manifest ships
FieldValueWhy it matters
Store listing description
"Seamlessly switch from search engines to Microsoft Bing directly in the Chrome browser address bar"This is the destination the extension's own description promises when you install it.
Manifest search_url
https://customserp.com/search.php?q={searchTerms}This is the address Chrome actually sends every search query to once the extension is installed.
Default-engine flag
is_default: trueThis tells Chrome to make the extension your active default search engine without asking which one you want.
Internal engine name
chrome.storage.sync: {defaultSettings: {searchEngine: "bing"}}The code stores this label internally, but no request in the extension is ever sent to bing.com.
03EvidenceTHIRD PARTY LIST
Where every search query actually goes
  • customserp.com

    Receives every raw search query typed into the address bar. It is not a known Microsoft or Bing property and has no established privacy track record.

04EvidenceARTIFACT
Reproduce it yourself

Reads an unpacked extension's manifest.json and default-locale messages.json and prints the advertised description next to the actual search_provider destination.

RequiresNode.js 14+
check_search_provider.js · js
#!/usr/bin/env node
// check_search_provider.js
// Reads an unpacked extension's manifest.json and default-locale messages.json,
// then prints the declared search destination next to the store description
// so you can see whether they match.
const fs = require('fs');
const path = require('path');

const dir = process.argv[2];
if (!dir) {
  console.error('Usage: node check_search_provider.js <unpacked-extension-dir>');
  process.exit(1);
}

const manifest = JSON.parse(fs.readFileSync(path.join(dir, 'manifest.json'), 'utf8'));
const locale = manifest.default_locale || 'en';
const messages = JSON.parse(
  fs.readFileSync(path.join(dir, '_locales', locale, 'messages.json'), 'utf8')
);

const provider = manifest.chrome_settings_overrides && manifest.chrome_settings_overrides.search_provider;
const description = messages.appDesc && messages.appDesc.message;

console.log('Advertised in store description:');
console.log('  ' + description);
console.log();
console.log('Actual search_provider in manifest.json:');
console.log('  name:        ' + (provider ? provider.name : '(none declared)'));
console.log('  search_url:  ' + (provider ? provider.search_url : '(none declared)'));
console.log('  is_default:  ' + (provider ? provider.is_default : '(none declared)'));

if (provider && description && /bing/i.test(description) && !/bing\.com/i.test(provider.search_url)) {
  console.log();
  console.log('MISMATCH: description references Bing, but search_url does not point at bing.com.');
}
How to run it
  1. 1
    Unpack the extension's .crx into a folder using any CRX viewer.
  2. 2
    Run 'node check_search_provider.js <folder>'.
  3. 3
    Compare the printed description to the printed search_url.
05EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

Where it sends data

Destinations our analysis observed Search Switch contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • customserp.com

    Search Switch sends data to customserp.com. No other extension we have analysed sends data here.

Updated 30 September 2026ofhljlgmgfgekggkmbjpjgaaghedbjnl