Skip to content
 
 

Latest commit

 

History

54 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

New Google Unlocked

A maintained, hardened fork of Ibit-to/google-unlocked that uncensors Google search results, modernized for current Chrome.

Google omits search results that were the subject of a DMCA / copyright takedown and replaces the entry with a footer link to a Lumen Database notice. This extension reads those Lumen notices, extracts the removed URLs, and renders them back inline at the bottom of the SERP, alongside Wayback Machine and archive.ph fallbacks so the pages are actually readable.

Why this fork

The original extension stopped loading in current Chrome because it was Manifest V2 (Cannot install extension because it uses an unsupported manifest version). The upstream repo also has an open XSS in the Lumen-response renderer. This fork:

  • Ports to Manifest V3 so it loads in Chrome 110+, Edge, Brave, Opera, Vivaldi
  • Fixes the XSS in u.js (all Lumen-derived strings now go through an HTML escaper; injected links get rel="noopener noreferrer")
  • Replaces chrome.webRequest CORS rewriting with declarativeNetRequest (a static ruleset that sets Access-Control-Allow-Origin: * on Lumen + chillingeffects responses, gated by declarativeNetRequestWithHostAccess)
  • Adds new bypasses: auto-applies filter=0, pws=0, nfpr=1 to disable Google's result clustering, personalization, and silent query rewriting
  • Adds a "Web only" pill that re-runs the current SERP with udm=14 (plain web results, no AI Overview / SGE block)
  • Adds Wayback + archive.ph links next to every revealed takedown domain
  • Re-adds legacy chillingeffects.org support (Lumen's previous hostname, still referenced in some Google takedown footers)

Install (manual, unpacked)

The signed Chrome Web Store and Firefox AMO listings were taken down years ago. Install unpacked:

Chrome / Edge / Brave / Opera / Vivaldi

  1. Download or git clone https://github.com/momenbasel/new-google-unlocked
  2. Open chrome://extensions (or edge://extensions, brave://extensions, etc.)
  3. Toggle Developer mode (top-right)
  4. Click Load unpacked, select the extension/ directory of this repo
  5. Google a query that has takedowns - the panel appears at the bottom of the SERP

Userscript (Tampermonkey / Violentmonkey / Greasemonkey)

Install google-unlocked.user.js directly. The userscript path is unchanged from upstream and works in Firefox.

Firefox (unsigned, temporary)

Mozilla AMO is gone. To run as a temporary extension:

  1. about:debugging#/runtime/this-firefox -> Load Temporary Add-on
  2. Select extension/manifest.json
  3. The add-on unloads on Firefox restart (this is a Firefox limitation, not the extension's)

What it touches

File Purpose
extension/manifest.json MV3 manifest, host_permissions, declarativeNetRequest ruleset declaration
extension/rules.json DNR static rules that add Access-Control-Allow-Origin: * to Lumen + chillingeffects
extension/u.js Content script - parses takedown footer, fetches Lumen notice, renders unlocked panel, applies SERP query unlocks, injects udm=14 pill
extension/jquery-3.3.1.min.js Bundled jQuery (vendored upstream; left as-is)
google-unlocked.user.js Standalone userscript build, no extension APIs

Permissions justification

Permission Why
declarativeNetRequestWithHostAccess Add Access-Control-Allow-Origin: * on Lumen / chillingeffects responses so the content script can XHR them from the google.com origin. Only fires when the extension already has host permission for both initiator and target.
host_permissions: google.* (every TLD) Run the content script on Google SERPs across all country domains. Same surface as upstream.
host_permissions: lumendatabase.org, chillingeffects.org XHR target for the takedown notice pages whose URLs Google embeds in SERP footers.

No webRequest, no tabs, no cookies, no storage, no remote-code execution. The full source is in this repo - read it.

SERP query parameters this extension sets

When you land on a Google SERP that has a q= and does not already carry our gu_unlocked sentinel, the extension does one in-tab redirect to the same URL with:

Param Effect
filter=0 Disables Google's "omitted similar results" clustering
pws=0 Disables personalized results for this query
nfpr=1 Disables Google's silent "search instead for ..." query rewrite
gu_unlocked=1 Tombstone; prevents re-redirect on the same navigation

If you remove any of those params manually from the URL bar, the extension will not re-add them on the same query.

Security notes

The XSS that was forward-ported in #4 (upstream) and never landed: the regex capture class="infringing_url">([^\s-<]+) in u.js does not exclude ", >, or &, so a crafted Lumen notice could break out of an href attribute and inject an event handler. This fork escapes all Lumen-derived strings before insertion via an escapeHTML helper, and every injected <a> carries rel="noopener noreferrer".

Report further issues at Issues.

Versioning

  • v2.1.0 - this fork, MV3 + XSS-safe panel + bypass additions
  • v1.5 - last upstream release (MV2, no longer Chrome-loadable)

Credits

License

Upstream had no LICENSE file. This fork inherits the same status. If the upstream author adds a license, this fork will follow.

Releases

Packages

Contributors

Languages