CRX aminer

Starting analysis...

Extension icon

Open AI Chat GPT For Email - Chatgpt Email - GMPlus

Version 2.0.21 View in Chrome Web Store

Last scanned: 2 months ago | force re-scan

Extension Details

Developer: https://gmplus.io/
Rating: 4.2 ★ (83 ratings)
Users: 40,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a moderate user base of 40,000 users and a decent rating of 4.2 stars, suggesting reasonable user satisfaction. The developer provides a website (gmplus.io) which adds some legitimacy. However, the relatively low number of reviews (83) compared to the user count may indicate limited user engagement or feedback.

Concerns:

The primary concern is the broad host permissions that allow access to all OpenAI domains (*.openai.com), which could potentially be exploited beyond the stated email functionality. While access to Gmail is expected for an email enhancement tool, the combination of Gmail and OpenAI access creates a pathway for sensitive email data to be processed by external AI services. The storage permission, while necessary for functionality, allows the extension to retain user data locally.

The extension's access to Gmail content scripts means it can read and modify email content, which is inherently sensitive. The broad OpenAI permissions raise questions about data handling and whether user emails might be sent to OpenAI servers without explicit user awareness.

Recommendations:

Consider using this extension in a separate Chrome profile dedicated to non-sensitive email accounts. Review the extension's privacy policy carefully to understand how your email data is processed. Monitor your OpenAI account for any unexpected API usage if you have one linked. Regularly review what data the extension has stored locally through Chrome's extension management settings.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://mail.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.