CRX aminer
Extension icon

Emoboard Emoji Keyboard

Version 1.0.3 View in Chrome Web Store

Last scanned: about 13 hours ago

Extension Details

Rating: 4.8 ★ (26 ratings)
Users: 20,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a decent user base of 20,000 users and maintains a strong 4.8-star rating from 26 reviews, suggesting users find it functional. However, the lack of visible developer information and company details reduces transparency and accountability.
Concerns: The primary concern is the excessive permissions for what should be a simple emoji keyboard tool. The <all_urls> host permissions and content script injection capabilities are completely unnecessary for an emoji keyboard, which should only need to insert emoji characters into text fields. These broad permissions create significant security risks, allowing the extension to access sensitive data on banking sites, social media, email platforms, and any other websites you visit. The combination of scripting permissions with universal website access means this extension could potentially log keystrokes, steal credentials, or modify website content across the entire web.
Recommendations: Given the high risk level, consider running this extension in a separate Chrome profile dedicated to non-sensitive browsing if you must use it. Better yet, look for alternative emoji keyboards with more appropriate, limited permissions. Most operating systems and many websites now have built-in emoji support that would be safer to use. If you continue using this extension, avoid accessing sensitive websites like banking or work-related sites while it's enabled, and regularly monitor your accounts for suspicious activity.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.