CRX aminer
Extension icon

SCheckPro

Version 16.32 View in Chrome Web Store

Last scanned: about 16 hours ago

Extension Details

Developer: http://spineditor.com/
Rating: 4.3 ★ (48 ratings)
Users: 50,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a moderate user base of 50,000 users and a decent rating of 4.3 stars, suggesting some level of user satisfaction. However, the limited number of reviews (48) relative to the user count raises questions about engagement. The developer website (spineditor.com) provides some transparency, though more detailed developer information would strengthen trust.

Concerns:

The extension exhibits several red flags that justify the high-risk classification. The combination of broad host permissions (*://*/*) with content script injection capabilities creates a powerful attack surface that could be exploited maliciously. The tabs permission allows extensive browser manipulation beyond what many legitimate extensions require. The overly broad permissions suggest the extension has access to far more data and functionality than typical productivity tools need. The lack of a clear description makes it impossible to verify if these permissions are justified for the extension's intended purpose.

Recommendations:

Given the high-risk nature, consider running this extension in a separate Chrome profile to isolate potential security impacts. Before installation, research the extension's specific functionality to determine if the extensive permissions are truly necessary. Monitor your browsing behavior and sensitive accounts after installation for any unusual activity. Consider alternative extensions with more limited permissions if similar functionality is available. Regularly review and audit installed extensions, removing those that aren't essential.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.