You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I reviewed the current SearchJumper source code on GitHub, including the generated "searchJumper.user.js", and I found a few privacy/security issues that I think are worth clarifying or improving.
The main issue is the privacy wording compared to the actual network behavior.
The README currently says things such as:
“Fully open source without any privacy collection, spam or third-party libraries.”
It also states that all data stays local and that there is no server interaction.
The privacy policy also says that SearchJumper does not share personal information with third parties.
However, the current code does make several external requests.
The most important example is search suggestions. SearchJumper automatically sends the contents of the SearchJumper search input to a third-party suggestion provider while the user is typing.
For non-Chinese users, Google is selected by default. For "zh-CN", Baidu is selected by default. Bing can also be selected manually.
The input handler calls "getSuggest()" roughly 200 ms after typing, and the complete current search text is then included in requests such as:
This means that text typed into the SearchJumper field can be sent to Google before the user has submitted the search.
I don't think this necessarily means SearchJumper is intentionally tracking users. The suggestion provider can be changed or disabled in the settings. However, this behavior should, in my opinion, be explicitly mentioned in the privacy policy, because the current wording gives the impression that no user data is transmitted to third parties at all.
There are also other external connections that would be useful to document, including:
"search.hoothin.com"
"webdav.hoothin.com"
"global.bing.com"
Google/Bing/Baidu suggestion services
external favicon/icon URLs
user-configured WebDAV servers and search/API endpoints
The WebDAV feature is optional and clearly related to synchronization, so I don't consider that hidden tracking. However, when enabled, SearchJumper uploads data such as "sitesConfig.json", "inPageRule.json", and timestamps to the configured WebDAV server.
Another security concern is the very broad userscript permissions:
The current source does not appear to abuse these permissions, but "@connect *" gives the script permission to communicate with any remote host. It would be safer to restrict this to the domains that are actually required, if technically possible.
Because this dependency is loaded remotely and is not pinned to an immutable hash/version, it creates a supply-chain trust dependency outside the main SearchJumper source file. The current dependency does not appear malicious, but changing it later could change runtime behavior without the main userscript necessarily changing in an obvious way.
One more thing I noticed is that the configuration page receives the entire "searchData" object through:
"window.postMessage(..., '*')"
If WebDAV is configured, "searchData" may contain the WebDAV host, username and password.
I did not find code that secretly sends those credentials to another third party, but exposing the full configuration object to page JavaScript increases the security boundary. It may be worth limiting the data passed through "postMessage" and avoiding ""*"" as the target origin where possible.
To be clear, I did NOT find evidence of traditional hidden analytics or spyware behavior. I did not find Google Analytics, Sentry, Mixpanel, PostHog, Hotjar, Clarity, Matomo, telemetry beacons, automatic cookie uploading, browser-history uploading, geolocation collection, or automatic uploading of webpage contents.
So my main concern is not that SearchJumper appears malicious.
The concern is that the privacy documentation currently makes stronger claims than the actual implementation supports.
I think the best improvements would be:
Explicitly disclose that search suggestion text is sent to Google/Baidu/Bing depending on the selected provider.
Explain that Google suggestions are enabled by default for most users.
Update wording such as “no server interaction” so it accurately reflects the external requests SearchJumper performs.
Document the optional WebDAV synchronization behavior and what files/data are uploaded.
Consider making search suggestions opt-in or disabled by default for privacy-focused users.
Pin or otherwise secure the remotely loaded "@require" dependency.
Avoid exposing WebDAV credentials through "window.postMessage(..., '*')" where possible.
I am sending this as constructive feedback because SearchJumper otherwise appears to make a serious effort to stay open source and privacy-focused, and clearer documentation would make the privacy claims much stronger and easier to trust.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Hi,
I reviewed the current SearchJumper source code on GitHub, including the generated "searchJumper.user.js", and I found a few privacy/security issues that I think are worth clarifying or improving.
The main issue is the privacy wording compared to the actual network behavior.
The README currently says things such as:
“Fully open source without any privacy collection, spam or third-party libraries.”
It also states that all data stays local and that there is no server interaction.
The privacy policy also says that SearchJumper does not share personal information with third parties.
However, the current code does make several external requests.
The most important example is search suggestions. SearchJumper automatically sends the contents of the SearchJumper search input to a third-party suggestion provider while the user is typing.
For non-Chinese users, Google is selected by default. For "zh-CN", Baidu is selected by default. Bing can also be selected manually.
The input handler calls "getSuggest()" roughly 200 ms after typing, and the complete current search text is then included in requests such as:
"https://suggestqueries.google.com/...&q="
This means that text typed into the SearchJumper field can be sent to Google before the user has submitted the search.
I don't think this necessarily means SearchJumper is intentionally tracking users. The suggestion provider can be changed or disabled in the settings. However, this behavior should, in my opinion, be explicitly mentioned in the privacy policy, because the current wording gives the impression that no user data is transmitted to third parties at all.
There are also other external connections that would be useful to document, including:
The WebDAV feature is optional and clearly related to synchronization, so I don't consider that hidden tracking. However, when enabled, SearchJumper uploads data such as "sitesConfig.json", "inPageRule.json", and timestamps to the configured WebDAV server.
Another security concern is the very broad userscript permissions:
"@match :///*"
"@grant GM.xmlHttpRequest"
"@grant GM_xmlhttpRequest"
"@connect *"
The current source does not appear to abuse these permissions, but "@connect *" gives the script permission to communicate with any remote host. It would be safer to restrict this to the domains that are actually required, if technically possible.
There is also an external "@require" dependency:
"https://update.greasyfork.org/scripts/484118/searchJumperDefaultConfig.js"
Because this dependency is loaded remotely and is not pinned to an immutable hash/version, it creates a supply-chain trust dependency outside the main SearchJumper source file. The current dependency does not appear malicious, but changing it later could change runtime behavior without the main userscript necessarily changing in an obvious way.
One more thing I noticed is that the configuration page receives the entire "searchData" object through:
"window.postMessage(..., '*')"
If WebDAV is configured, "searchData" may contain the WebDAV host, username and password.
I did not find code that secretly sends those credentials to another third party, but exposing the full configuration object to page JavaScript increases the security boundary. It may be worth limiting the data passed through "postMessage" and avoiding ""*"" as the target origin where possible.
To be clear, I did NOT find evidence of traditional hidden analytics or spyware behavior. I did not find Google Analytics, Sentry, Mixpanel, PostHog, Hotjar, Clarity, Matomo, telemetry beacons, automatic cookie uploading, browser-history uploading, geolocation collection, or automatic uploading of webpage contents.
So my main concern is not that SearchJumper appears malicious.
The concern is that the privacy documentation currently makes stronger claims than the actual implementation supports.
I think the best improvements would be:
I am sending this as constructive feedback because SearchJumper otherwise appears to make a serious effort to stay open source and privacy-focused, and clearer documentation would make the privacy claims much stronger and easier to trust.
All reactions