CRX aminer
Extension icon

Compras online Travel Club

Version 2.0.0 View in Chrome Web Store

Last scanned: about 10 hours ago

Extension Details

Developer: Air Miles España, S.A.
Rating: 1.8 ★ (54 ratings)
Users: 20,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension is published by Air Miles España, S.A., which appears to be a legitimate loyalty program company. However, the extremely low rating of 1.8 out of 5 stars from 54 reviews is a major red flag, suggesting significant user dissatisfaction or potential issues with the extension's functionality or behavior. With 20,000 users, it has moderate adoption but the poor reviews indicate serious problems.

Concerns:

The combination of broad host permissions (<all_urls>) with tabs permission creates a particularly concerning security profile. This allows the extension to access and potentially manipulate content on every website you visit, not just shopping sites where it would be expected to function. The tabs permission enables monitoring of your browsing activity across all tabs. For a shopping/travel extension, these permissions seem excessive and unnecessary. The storage permission, while common, combined with the broad access could enable extensive data collection about your browsing habits and personal information.

Recommendations:

Given the high risk profile and terrible user reviews, I strongly recommend avoiding this extension entirely. If you must use it for Air Miles benefits, run it in a completely separate Chrome profile dedicated only to shopping activities. Regularly review what data the extension has access to and consider alternative methods for accessing Air Miles benefits, such as using their website directly. The poor ratings suggest the extension may not even function properly, making the security risks unjustifiable.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.