CRX aminer
Extension icon

S3BucketList

Version 4.1.2 View in Chrome Web Store

Last scanned: 18 days ago | force re-scan

Extension Details

Rating: 3.5 ★ (2 ratings)
Users: 1,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has concerning trust indicators with only 1,000 users and a modest 3.5-star rating from just 2 reviews, suggesting limited adoption and user confidence. The lack of detailed developer information and missing description raises transparency concerns. The name "S3BucketList" suggests it's designed for AWS S3 bucket management, which would be a legitimate use case for developers and cloud administrators.
Concerns: The extension requests extremely broad permissions that appear excessive for S3 bucket management. The combination of webRequest, tabs, and <all_urls> host permissions creates a powerful surveillance capability that could intercept all web traffic, access sensitive data across all websites, and manipulate browser tabs. These permissions would allow the extension to potentially capture AWS credentials, API keys, or other sensitive information from any website. The storage permission, while less concerning individually, could be used to persist stolen data.
Recommendations: Given the high-risk permission combination and limited trust indicators, avoid installing this extension on your primary browser profile. If you must use it for legitimate S3 management tasks, create a dedicated Chrome profile with minimal sensitive data and use it only when accessing AWS services. Consider alternative S3 management tools with more transparent developers and narrower permission scopes. Monitor your AWS account activity closely if you choose to use this extension.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.