Is XFinderr. Search safe?
XFinderr is medium risk. Installing XFinderr Search replaces your default search engine with xfinderr.org, no consent prompt. Every address-bar query then goes to xfinderr.org. The override is declared in the manifest; no JS runs it, and it persists until removal.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Search engine replaced with xfinderr.org on install
Installing XFinderr Search replaces your default search engine with xfinderr.org, no consent prompt.
Every address-bar query then goes to xfinderr.org.
The override is declared in the manifest; no JS runs it, and it persists until removal.
You install the XFinderr. Search extension from the Chrome Web Store.
Chrome applies the search_provider override from the extension manifest, setting xfinderr.org as your default search engine.
No consent prompt is shown. Every address-bar query is routed to https://xfinderr.org/q?q={searchTerms} until the extension is removed.
manifest.json, the search_provider declaration that redirects all address-bar queries
// chrome_settings_overrides.search_provider is a Chrome Manifest V3 mechanism
// that registers a new search engine. When is_default is true, Chrome sets it
// as the browser default at install time without an additional user prompt.
//
// search_url template: GET https://xfinderr.org/q?q={searchTerms}
// Chrome substitutes {searchTerms} with whatever the user typed in the address
// bar before dispatching the HTTP request.
//
// suggest_url template: GET https://xfinderr.org/q/suggest.php?q={searchTerms}
// Called as the user types each keystroke to populate autocomplete suggestions —
// partial queries are transmitted before the user presses Enter.
//
// The extension declares no permissions[], no background service worker, and no
// content scripts. The entire behavior is encoded in this manifest declaration,
// executed by Chrome itself at install time.- xfinderr.org
Current search endpoint (v2.0.0.8 onward). Receives all address-bar queries as GET /q?q= parameters; partial keystrokes also transmitted via the suggest endpoint /q/suggest.php?q=.
- xfinder.pro
Original search endpoint (v2.0.0.7). Functionally identical to xfinderr.org, queries routed via GET /q?q= and autocomplete via /q/suggest.php?q=.