Privacy Essentials

duckduckgo.com/app
Privacy Essentials

Simple extension by DuckDuckGo, which grades the security of each site. Download: Chrome
Firefox

Open Source

Privacy Essentials Privacy Policy

Privacy Policy Summary

  • No need to register
  • The service makes critical changes to its terms without user involvement
  • This service provides an onion site accessible over Tor
  • You can delete your account and Duck Addresses
  • No personal search or browsing history is saved
  • Any liability on behalf of the service is only limited to the fees you paid as a user in the last 12 months or 100$
  • If you offer suggestions to the service, they may use that without your approval or compensation, but they do not become the owner
  • Invalidity of any portion of the Terms of Service does not entail invalidity of its remainder
  • There is a date of the last update of the agreements
  • The service is not responsible for linked or (clearly) quoted content from third-party content providers
  • The service is provided 'as is' and to be used at your sole risk
  • You agree not to use the service for illegal purposes
  • The service provider makes no warranty regarding uninterrupted, timely, secure or error-free service
  • The service assumes no liability for any damages the user incurs
  • The service does not guarantee accuracy or reliability of the information provided
  • This service does not guarantee that it or the products obtained through it meet your expectations or requirements

Score

C

Documents

Domains Covered by Policy

  • duckduckgo.com
  • 3g2upl4pq6kufc4m.onion
  • spreadprivacy.com
  • duckduckhack.com
  • donttrack.us
  • duck.co
  • duck.com

About the Data

This data is kindly provided by tosdr.org. Read full report at: #222

Privacy Essentials Source Code

Author

duckduckgo

Description

DuckDuckGo Privacy Essentials browser extension for Firefox, Chrome.

#browser-extension#chrome#duckduckgo#firefox#privacy#privacy-protection

Homepage

https://duckduckgo.com/app

Repository

  • LicenseApache-2.0
  • Created11 Dec 17
  • Primary languageJavaScript
  • Size124,379 KB
  • Stars1,492
  • Forks330
  • Watchers1,492

Language Usage

Language Usage

Project Health

Recent Commits

  • Tom Harber(13 Aug 26)

    feat: add noai URL param to chrome new tab page (#3637) * feat: add noai URL param to chrome new tab page * fix: fix broken tests for firefox * fix: flaky test

  • Sam Macbeth(06 Aug 26)

    Move web-ext to devDependencies (#3631) * Fix package-lock.json out of sync after build group bump The web-ext 10.5.0 upgrade pulls in addons-linter, whose addons-scanner-utils dependency declares an optional peer dependency on [email protected]. Dependabot's lockfile update omitted that peer's own dependency subtree (body-parser, accepts, etc.), so `npm ci` failed with "Missing: [email protected] from lock file" and related packages. Regenerating the lockfile with `npm install --package-lock-only` restores the missing entries. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_015nyF2deGZ9yWP89h9Art54 * Move web-ext to devDependencies web-ext is only used as a CLI build/packaging tool (web-ext build, web-ext run) and isn't imported by the shipped extension code, so it belongs alongside the other dev tooling (esbuild, sass, eslint) rather than in dependencies. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_015nyF2deGZ9yWP89h9Art54 --------- Co-authored-by: Claude <[email protected]>

  • dependabot[bot](06 Aug 26)

    Bump the build group across 1 directory with 5 updates (#3630) Bumps the build group with 4 updates in the / directory: [web-ext](https://github.com/mozilla/web-ext), [esbuild](https://github.com/evanw/esbuild), [sass](https://github.com/sass/dart-sass) and [yargs](https://github.com/yargs/yargs). Updates `web-ext` from 8.10.0 to 10.5.0 - [Release notes](https://github.com/mozilla/web-ext/releases) - [Commits](https://github.com/mozilla/web-ext/compare/8.10.0...10.5.0) Updates `esbuild` from 0.25.12 to 0.28.1 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md) - [Commits](https://github.com/evanw/esbuild/compare/v0.25.12...v0.28.1) Updates `eslint` from 9.39.2 to 9.39.4 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/compare/v9.39.2...v9.39.4) Updates `sass` from 1.97.3 to 1.102.0 - [Release notes](https://github.com/sass/dart-sass/releases) - [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md) - [Commits](https://github.com/sass/dart-sass/compare/1.97.3...1.102.0) Updates `yargs` from 18.0.0 to 18.1.0 - [Release notes](https://github.com/yargs/yargs/releases) - [Changelog](https://github.com/yargs/yargs/blob/main/CHANGELOG.md) - [Commits](https://github.com/yargs/yargs/compare/v18.0.0...v18.1.0) --- updated-dependencies: - dependency-name: web-ext dependency-version: 10.5.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: build - dependency-name: esbuild dependency-version: 0.28.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: build - dependency-name: eslint dependency-version: 9.39.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: build - dependency-name: sass dependency-version: 1.102.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: build - dependency-name: yargs dependency-version: 18.1.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: build ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

  • Sam Macbeth(06 Aug 26)

    Bump @duckduckgo/eslint-config to v0.2.1 (#3629) Updates eslint-plugin-n from v17 to v18, which adds the n/no-callback-literal rule. Rename the mock chrome.storage callback params in inject-chrome-shim.js from cb to respond so the rule doesn't mistake them for error-first Node callbacks. Co-authored-by: Claude <[email protected]>

  • github-actions[bot](06 Aug 26)

    Release 2026.8.6 [ci release] (#3628) Co-authored-by: sammacbeth <[email protected]>

  • Dave Vandyke(04 Aug 26)

    Remove Click to Load feature (#3625) Since we're turning the Click to Load feature off now, we can remove the dead code.

  • Dave Vandyke(03 Aug 26)

    Update tracker-surrogates dependency to 2.0.0 (#3624)

  • Dax Mobile(31 Jul 26)

    Update autoconsent to v16.19.0 (#3617) Co-authored-by: sammacbeth <[email protected]>

  • Maxim Tsoy(22 Jul 26)

    Remove cpm messaging queue (#3608) * Remove messaging queue in the embedded extension * add a timeout to the config refresh to prevent deadlocks * Add timeouts to all native messages * Ensure that dashboard updates are sent in order * Bump embedded version * Extend outer config refresh timeout above native timeout The outer scheduleConfigRefresh timeout was equal to the inner NATIVE_MESSAGE_TIMEOUT_MS used by embedded refreshRemoteConfig. Because Promise.race takes the first fulfillment, the outer timer (scheduled first) would resolve to null at nearly the same instant that the inner path fell back to a valid cached config, discarding it and forcing cpmStage to 'config_unavailable'. Extending the outer safety timeout above the native timeout lets the cached-config fallback settle first while still guarding against a truly hung refresh. * Remove redundant config refresh timeout Rely on the native messaging timeout so cached config fallback can win without a competing outer timer. Co-authored-by: Cursor <[email protected]> * Remove notify chain for dashboard updates * refactor the timeout --------- Co-authored-by: Cursor Agent <[email protected]>

  • Dave Vandyke(20 Jul 26)

    Remove myself as a pixel owner (#3611) Removing myself as a pixel owner, as I am leaving DuckDuckGo.

  • Dave Vandyke(20 Jul 26)

    Update the Playwright Firefox harness dependency repository (#3610) We have moved the harness repository[1] into the DuckDuckGo account, so let's update the dependency here to point to that. 1 - https://github.com/duckduckgo/firefox-webext-playwright-harness

  • Dave Vandyke(16 Jul 26)

    Fix a flake with the ATB integration tests (#3607) The initial exti request was sometimes firing before the request listener could be set up, which caused the ATB tests to hang. Let's add a two second timeout, to avoid failing when that happens.

  • Dave Vandyke(15 Jul 26)

    Update Playwright Firefox harness dependency to 0.3.0 (#3605)

  • Dave Vandyke(14 Jul 26)

    [DNR] Get the ddg2dnr unit tests running against Firefox too (#3595) So far, the Chrome build of the extension uses the MV3 APIs including the declarativeNetRequest (DNR) APIs for request blocking/redirection, but the Firefox build uses the MV2 APIs instead. Maintaining both MV2 and MV3 codepaths is expensive, so it would be nice to standardise to MV3 in the future. As a first step, let's get the DNR unit tests running against Firefox as well. That is worthwhile since the `declarativeNetRequest.testMatchOutcome` test cases are actually checking that the browser applies our DNR rules in the way that we are expecting. From there we should have more confidence to start adjusting the Firefox build.

  • Maxim Tsoy(13 Jul 26)

    CPM heuristic pixel fix (#3602) * fix the heuristic summary pixel * Bump the embedded release version

  • Dave Vandyke(10 Jul 26)

    [DNR] Split up the Smarter Encryption and Tracker Blocking reference tests (#3601) The Smarter Encryption and Tracker Blocking reference test assertions were running under one test group. This gave a muddied output (particular in the case of a test failure) and also meant that all the assertions shared the same two second timeout. This became a problem on Firefox, where the Tracker Blocking tests took longer than two seconds to run. Let's split out the tests now, ready for when we start running them against Firefox.

  • Dave Vandyke(10 Jul 26)

    [DNR] Avoid hardcoding the resource types where possible (#3596) In the future, we would like to run the `declarativeNetRequest.testMatchOutcome` unit tests against Firefox as well as Chrome, but it turns out that the `declarativeNetRequest.ResourceType` enum differs between the browsers, which will cause the tests to fail. Instead of hardcoding the resourceTypes therefore, let's make use of `declarativeNetRequest.ResourceType` where possible. When it's not, let's fall back to a conservative subset of the resource types that both browsers support.

  • Dave Vandyke(09 Jul 26)

    Update Playwright Firefox harness dependency to 0.2.0 (#3594)

  • Dax Mobile(08 Jul 26)

    Update autoconsent to v16.8.1 (#3593) Co-authored-by: muodov <[email protected]>

  • Dave Vandyke(08 Jul 26)

    Drop the Puppeteer dependency (#3589) We already use Playwright for the integration tests, so let's drop the Puppeteer dependency. For the cases where we were still using Puppeteer, we can switch to Playwright instead. Hopefully that should clear the way for us to start running the unit tests against Firefox in the future as well, since we already have a Firefox Playwright harness working for the integration tests.

  • Dax Mobile(08 Jul 26)

    Update autoconsent to v16.8.0 (#3590) Co-authored-by: sammacbeth <[email protected]>

  • Maxim Tsoy(24 Jun 26)

    Extra CPM breakage flags (#3575) * Implement additional CPM breakage flags * Reduce the number of native messages in CPM * add 2 more cpm stages * Add tests for diagnostics in embedded messaging * add unit tests * Reset the dashboard state on every top-level init * report reload loop in dashboard after popupFound * bump embedded version * type fix * fix tests * simplify serialization

  • Sam Macbeth(24 Jun 26)

    Set heuristic mode config option based on user preference (#3571) * Set heuristic mode config option based on user preference * Lint fix * Update pixel parameters * Update shape of Autoconsent settings message response. Move settings messaging call inside the init response. * Add missing mock * Lint fix * Bump autoconsent * Standardize heuristic action check * Updated heuristic mode parameter * Fix settingsToHeuristicModeName docs * Fix typing narrowing of heuristicMode * Cover all heuristic off cases * Fix weak equalities * Fix comment * Remove checkAutoconsentSettingEnabled and add tests for checkAutoconsentSetting * Bump autoconsent to 16.0.0

  • Maxim Tsoy(18 Jun 26)

    CPM: do not cache consentManaged flag per domain (#3570) * ts lint fixes * stop caching consentManaged flag per domain * remove unused variable * Bump embedded extension

  • Dax Mobile(15 Jun 26)

    Update autoconsent to v14.95.0 (#3569) Co-authored-by: sammacbeth <[email protected]>

  • Dave Vandyke(11 Jun 26)

    Update Playwright Firefox harness dependency to 0.1.1 (#3565)

  • Dave Vandyke(11 Jun 26)

    Update Playwright dependency to 1.60.0 (#3564) Chrome 148 is included with the update, which broke one of our integration tests, since page-initiated requests to local networks are now blocked by default. Firefox 150 is included as well, which exacerbated an existing flake in the request blocking tests. Let's fix that here too. Let's also remove the background ServiceWorker retry fallback, as that Playwright issue has been fixed[1] upstream now. 1 - https://github.com/microsoft/playwright/issues/39075

  • Dave Vandyke(10 Jun 26)

    Remove the Chrome MV2 build and test target (#3563) Now that we've got the integration tests running on Firefox, we no longer need the Chrome MV2 build target or test runner. Let's clear that all up now. While we're at it, let's tidy up: - Related checks in the tests for manifest version that no longer make sense (since Chrome test runs are always MV3 now). - Unnecessary plumbing/abstractions that turned out not to be necessary for the Firefox test runner. - Unnecessary separate GitHub workflow. - Redundant routeExtensionRequests helper.

  • Dave Vandyke(08 Jun 26)

    Add experimental Firefox integration test support (#3520) Add experimental Firefox support to the integration tests, which can be called with the `npm run playwright-firefox` command. Makes use of our experimental harness[1]. Being able to run our integration tests against Firefox is important for a number of reasons: 1. A large portion of the extension users run Firefox, and so we want to ensure it works correctly for them. 2. We need Firefox test coverage to help make larger/riskier changes to the Firefox extension, like migrating to MV3. 3. We need to remove the existing `playwright-mv2` runner, which relies on Chrome MV2 support, which has now been removed. Not only does that runner not test what our users really see (e.g. it's the wrong browser), but it is also keeping us stuck on an older version of Playwright, for the corresponding Chrome MV2 compatibility. Assuming the Firefox harness works reliably, we'll remove the `playwright-mv2` runner, `chrome-mv2` build target, and update the Playwright dependency as a follow-up. 1 - https://github.com/kzar/firefox-webext-playwright-harness

  • Dax Mobile(27 May 26)

    Update autoconsent to v14.85.0 (#3554) Co-authored-by: muodov <[email protected]>

Privacy Essentials Security

5.7/10

Repo Security Summary

Updated 27 Jul 26

  • PackagingN/A
  • Dangerous-Workflow10/10
  • Maintained10/10
  • Code-Review10/10
  • CII-Best-Practices0/10
  • Binary-Artifacts10/10
  • Token-Permissions0/10
  • Pinned-Dependencies3/10
  • Security-Policy0/10
  • License10/10
  • Fuzzing0/10
  • Branch-ProtectionN/A
  • Signed-Releases0/10
  • SAST9/10

Privacy Essentials Website

Website

DuckDuckGo - Protection. Privacy. Peace of mind.

The Internet privacy company that empowers you to seamlessly take control of your personal information online, without any tradeoffs.

Redirects

Redirects to https://duckduckgo.com/&quot;https:/html.duckduckgo.com/html&quot;

Security Checks

All 65 security checks passed

Server Details

  • IP Address52.149.246.39
  • LocationDulles,Virginia,United States of America,NA
  • ISPMicrosoft Corporation
  • ASNAS8075

Associated Countries

  • USUS

Safety Score

Website marked as safe

100%

Blacklist Check

duckduckgo.com was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

Privacy Essentials Reviews

More Browser Extensions

About the Data: Privacy Essentials

Edit Privacy Essentials Data

You can edit Privacy Essentials's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external sources, a list of these can be found data documentation.

Origin Data

Modify Data

API

You can access Privacy Essentials's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/privacy-essentials

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share Privacy Essentials

Help your friends compare Browser Extensions, and pick privacy-respecting software and services.
Share Privacy Essentials and Awesome Privacy with your network!