CRX aminer
Extension icon

Redirect Path

Version 3.0 View in Chrome Web Store

Last scanned: 5 days ago | force re-scan

Extension Details

Developer: www.ayima.com
Rating: 4.3 ★ (195 ratings)
Size: 6.06MiB
Last Updated: June 7, 2024
Users: 300,000
Developer Info: Ayima Ltd16 Saint John's Lane London EC1M 4BS GB

Context-Aware Verdict

CRITICAL
Risk Level
Trust Factors:
- The extension has a relatively high number of users (300,000), which could indicate some level of trust.
- The developer is a legitimate company (Ayima Ltd), which adds some credibility.
- However, the extension's description is vague and does not provide much context about its intended purpose.
Concerns:
- The extension requests several high-risk permissions (webRequest, webNavigation, clipboardWrite) that could potentially be abused for malicious purposes, such as intercepting and modifying web requests, tracking browsing activity, and modifying clipboard content.
- It has broad host permissions (https://*/*, http://*/*) and can inject content scripts into any website, which could lead to privacy violations or data theft.
- The overall risk level is rated as "Critical" by the security findings, indicating a high potential for abuse or compromise.
Recommendations:
- Exercise extreme caution when using this extension, as it has access to sensitive data and browsing activity.
- Consider running the extension in a separate Chrome profile or a sandboxed environment to isolate it from your primary browsing activities.
- Closely monitor the extension's behavior and network traffic for any suspicious activity.
- If possible, seek alternative extensions with similar functionality but fewer high-risk permissions and better transparency about their intended purpose.
- Regularly review and update the extension to ensure you have the latest version with any potential security fixes.

Security Analysis

CRITICAL
Overall Risk
Based on 6 total findings, ranked without considering overall context, including 5 high-risk and 1 medium-risk findings.
HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: clipboardWrite
This extension has the clipboardWrite permission. Can modify clipboard content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.