CRX aminer
Extension icon

Group Extractor & Export Group Members - extractor.plus

Version 1.6.4 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Developer: extractor.plus
Rating: 4.2 ★ (302 ratings)
Users: 2,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a moderate user base of 2,000 users with a decent 4.2-star rating from 302 reviews, suggesting some level of user satisfaction. However, the developer "extractor.plus" lacks established reputation or transparency about their identity and practices. The extension's purpose of extracting Facebook group members raises inherent privacy concerns, as it involves harvesting personal data from social networks.

Concerns:

The combination of cookies and webRequest permissions is particularly concerning for a group extraction tool. While storage permissions are reasonable for data export functionality, the webRequest permission allows the extension to intercept and potentially modify all web traffic, which goes beyond what's necessary for simply extracting group member information. The cookies permission could enable unauthorized access to user accounts or session hijacking. The extension's access to Facebook groups means it can potentially harvest sensitive personal information from group members who haven't consented to data collection.

Recommendations:

Given the high-risk permissions and data harvesting nature, consider running this extension in a separate Chrome profile to isolate it from your main browsing activities. Only use it when absolutely necessary and disable it when not in use. Be aware that using such tools may violate Facebook's terms of service and could result in account restrictions. Consider whether the group extraction functionality is worth the privacy and security risks, especially given the broad permissions requested.

Findings

HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://www.facebook.com/. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.