CRX aminer
Extension icon

ColorPick Eyedropper

Version 1.0.1 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Rating: 5.0 ★ (1 rating)
Users: 891

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has concerning trust indicators - only 891 users with just 1 review (despite a 5.0 rating), no clear author information, and missing developer details. The lack of transparency around the developer identity is a significant red flag for a tool requesting such extensive permissions.
Concerns: The extension's permissions are disproportionately broad for a simple color picker tool. While color picking typically requires some web access to sample pixels, the combination of all-URL host permissions with content script injection capabilities creates a powerful surveillance mechanism. The extension can access every website you visit, read all page content including passwords and personal information, and potentially modify website behavior. The storage permission, while less concerning individually, could be used to collect and retain harvested data.
Recommendations: Given the high risk profile, avoid installing this extension on your primary browser profile. If you must use it, create a separate Chrome profile specifically for this tool and only use it on non-sensitive websites. Consider well-established alternatives like built-in browser developer tools or reputable color picker extensions with more limited permissions and transparent developers. The broad permissions combined with the lack of developer accountability make this extension unsuitable for environments containing sensitive information.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.