Firefox Add-ons Verified

Better Search for Google

by Dracon · 2 users
13ed7718-c46d-5938-9bad-fbd3d3540bac | v1.1.1
63/ 100
MEDIUM risk
+3 since v1.0.0
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
4 weeks ago
Version
v1.1.1
Artifact
SHA256 234…D3C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

34 detail rows

YARA Rule Matches

9 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 3
content-scripts/content.jsbackground.jschunks/dashboard-CWHY9CJT.js
-
LOWpostinstall crypto operations 2
chunks/dashboard-CWHY9CJT.jsbackground.js
-
LOWpostinstall file manipulation 5
chunks/dashboard-CWHY9CJT.jssearch.htmlcontent-scripts/content.js +2 more
-
LOWpostinstall environment access 1
chunks/dashboard-CWHY9CJT.js
-
LOWpostinstall obfuscation 3
chunks/dashboard-CWHY9CJT.jsMETA-INF/manifest.mfMETA-INF/cose.manifest
-
LOWpostinstall network communication 3
chunks/dashboard-CWHY9CJT.jscontent-scripts/content.jsbackground.js
-
LOWpostinstall system command 7
assets/welcome-Y5ANY7Y0.csspopup.htmlchunks/dashboard-CWHY9CJT.js +4 more
-
LOWpostinstall file download 5
chunks/_virtual_wxt-html-plugins-DPbbfBKe.jscontent-scripts/content.jsbackground.js +2 more
-
LOWNoUseWeakRandom 1
content-scripts/content.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

683 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Dracon

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

47
Noisy-finding weight
x1.00
Publisher domain
dracon.uk
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
17
Portfolio

12 evidence rows available.

Finding Categories

3
Network
683
IoC Indicators

YARA Rules Matched

9 rules(30 hits)
postinstall persistence mechanism postinstall crypto operations postinstall file manipulation postinstall environment access postinstall obfuscation postinstall network communication postinstall system command postinstall file download NoUseWeakRandom

Requested Permissions

39 permissions
tabs
Medium
declarativeNetRequestWithHostAccess
Low
storage
Low
*://www.google.com/*
Low
*://www.google.co.uk/*
Low
*://www.google.ca/*
Low
*://www.google.com.au/*
Low
*://www.google.de/*
Low
*://www.google.fr/*
Low
*://www.google.es/*
Low
*://www.google.it/*
Low
*://www.google.nl/*
Low
*://www.google.pl/*
Low
*://www.google.jp/*
Low
*://www.google.com.br/*
Low
*://www.google.in/*
Low
*://www.google.com.mx/*
Low
*://www.google.co.nz/*
Low
*://www.google.com.ar/*
Low
*://www.google.com.sa/*
Low
*://www.google.se/*
Low
*://www.google.no/*
Low
*://www.google.dk/*
Low
*://www.google.fi/*
Low
*://www.google.co.za/*
Low
*://www.google.com.pk/*
Low
*://www.google.com.eg/*
Low
*://www.google.com.vn/*
Low
*://www.google.co.id/*
Low
*://www.google.com.my/*
Low
*://www.google.com.sg/*
Low
*://www.google.co.kr/*
Low
*://www.google.com.tw/*
Low
*://www.google.com.hk/*
Low
*://www.google.com.ph/*
Low
*://www.google.com.ng/*
Low
*://www.google.com.gh/*
Low
*://www.google.co.ke/*
Low
*://www.google.com.bd/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The manifest (manifest.json) declares the tabs permission, which is normal for an extension that needs to read the URL of the current Google Search page in order to apply its filtering logic. No other high‑risk permissions (such as cookies, webRequest, or proxy) are present. Two JavaScript files make network requests: chunks/_virtual_wxt-html-plugins-CdCj8_S8.js:1 and content-scripts/content.js:25 each contain a fetch call. These calls are the only active runtime behavior observed and are consistent with downloading a blocklist or updating filter rules.

The bulk of the findings are domain IoCs extracted from the code (extracted_from_files). The list includes domains such as fool.com, 3commas.io, cryptohopper.com, icobench.com, icotracker.com, icodrops.com, swcpoker.eu, coinsutra.com, and marketwatch.com. Many of these sites are legitimate news or cryptocurrency‑related sites that are commonly added to content‑farm or low‑quality‑result blocklists. The XIOC extractor is known to flag any literal string that looks like a domain, even when the string is merely part of a hard‑coded blocklist. Because the extension’s purpose is to block “content farms, spam sites, and low‑quality results,” the presence of a large static list of domains is expected and does not imply that the extension is contacting those sites for nefarious purposes.

No malware‑signature or malware findings are present, and the extension contains no obfuscation, secret extraction, or code‑smell findings that would suggest hidden payloads. The only permission request is tabs, and the network activity is limited to simple fetch calls, which aligns with a benign content‑filtering workflow.

A skeptic might argue that the many listed domains could be used to track users or that the fetch calls could exfiltrate browsing data to third‑party servers. However, the evidence shows the calls are issued from static bundle files that are typically employed to retrieve an updated blocklist; there is no indication of data being sent out from the user’s browser, nor are there any write‑to‑external‑host requests beyond the initial list download. The domains flagged as IoCs are not obscure command‑and‑control addresses; they are public sites that a filter would normally block, which strongly suggests the findings are false positives generated by the IoC extractor rather than evidence of malicious intent.

In conclusion, the extension’s behavior matches its description of improving Google Search results by blocking low‑quality sites. The high count of IoC findings stems from the blocklist content rather than malicious activity, and there is no technical evidence of credential theft, hijacking, or proxyware. Users can consider the extension safe for its intended purpose, though they should remain aware that any filter based on domain lists can occasionally block legitimate content.

Key Reasons

  • Only the tabs permission is requested, which is typical for search‑filter extensions
  • Network activity is limited to fetch calls in two JavaScript files, consistent with blocklist updates
  • All domain findings are likely entries in a hard‑coded blocklist rather than C2 addresses
  • No malware signatures, obfuscation, or credential‑related code were detected
  • Extension name does not imitate any known product, eliminating impersonation concerns

False Positive Considerations

  • IoC extractor flags all literal domain strings in blocklist
  • High finding count due to bundled blocklist entries

Reviewed 2026-05-31; recommended action: no action; model confidence 85%.

Firefox version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
63
Change since first
+3
Change from previous
+3
Versions:
First analyzed version
1.0.0
May 30, 2026
Risk range
60 to 63
Across analyzed versions
Latest analyzed version
1.1.1
Sep 3, 2026
Selected version
medium
Version
v1.1.1
4 weeks ago
Risk score
63
Findings
717
Change vs previous
+3

Pick any point on the chart to explore that version's code below.

About This Extension

Better Search for Google removes the noise from your search results. Block 500+ content farms, AI spam sites, clickbait publishers, and low-quality domains. Filter out login walls, paywalled articles, and affiliate-heavy reviews. Features: • Toggle categories: AI Spam, Content Farms, Ad-Heavy Sites, Login Walls, Low-Quality Aggregators • Platform Preferences: Prefer, Exclude, or Only show specific sites (YouTube, Reddit, GitHub, etc.) • Search filters: Time range, language, region, safe search • Clean UI: Hide Google's clutter, sign-in prompts, and AI overviews • Fast: Results filtered at the URL level, no page reloads Works on <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/9eedbceb27e33fc775eec3ef277a8a4333b6e5067d818dade5ab40da7cbe3896/http%3A//Google.com" rel="nofollow">Google.com</a> and 30+ international Google domains. Built by someone sick of Google's increasingly useless results. Free and open source.

Frequently Asked Questions