DuckDuckGo Search & Tracker Protection
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v2026.8.6
- Artifact
- SHA256 437…997
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceDuckDuckGo
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
Requested Permissions
10 permissionsAccess and modify data on every website you visit
Intercept, modify, and block all network requests
Block network requests before they complete
AI Security Report
AI Security Review
Evidence context: threat category typosquatting; evidence quality moderate.
This extension presents a significant brand impersonation concern. The extension is named "DuckDuckGo Search & Tracker Protection" and describes itself as providing "private search with optional AI, private browsing, and ad blocking" — features consistent with DuckDuckGo's legitimate offerings. However, the developer_name field is completely empty, which is a critical red flag. DuckDuckGo is a well-known privacy company with official extensions that include proper developer attribution. An extension claiming to be from DuckDuckGo without any developer identification is inconsistent with how legitimate branded extensions are published.
The technical findings themselves are benign. The manifest-analysis findings in manifest.json show tabs and
The strongest counterargument is that the technical code analysis shows no malicious behavior — no malware, no obfuscation, no suspicious domains. However, this misses the core security issue: brand impersonation is a threat regardless of what the code does. An extension can be technically benign while still being deceptive if it misleads users into believing it's from a trusted brand. The empty developer field is the smoking gun here. If this were a legitimate DuckDuckGo extension, it would have proper developer attribution. The combination of using DuckDuckGo's brand name with anonymous publication is the defining risk factor, not the generic network findings that populate the report.
Key Reasons
- Empty developer_name field for extension claiming DuckDuckGo brand
- No malware signatures or obfuscation detected in code
- Network findings are generic API detections, not suspicious domains
- High user count (1.1M) increases potential impact if impersonation is confirmed
False Positive Considerations
- Generic network API detections (fetch, xmlhttprequest, jquery_ajax)
- Expected permissions for privacy extension (tabs, all_urls)
Reviewed 2026-05-23; recommended action: escalate; model confidence 85%.
Firefox version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
DuckDuckGo No-AI Search
DuckDuckGo
Duckduckgo
Duckduckgo
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software