CRX aminer
Extension icon

Redirect Path

Version 3.0 View in Chrome Web Store

Last scanned: about 1 month ago | force re-scan

Extension Details

Developer: Ayima UK Ltd
Rating: 4.4 ★ (196 ratings)
Users: 300,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a solid user base of 300,000 users and maintains a good rating of 4.4/5 from 196 reviews. Ayima UK Ltd appears to be a legitimate company in the digital marketing/SEO space, which aligns with the extension's purpose of tracking redirects and analyzing website paths. The name "Redirect Path" clearly indicates its functionality.

Concerns:

The extension's permission set is extremely broad for its stated purpose. The webRequest and webNavigation permissions allow complete monitoring of all web traffic, while clipboardWrite enables modification of clipboard content without clear justification. The combination of broad host permissions across all HTTP/HTTPS sites with content script injection on all URLs creates a powerful surveillance capability. These permissions far exceed what would typically be necessary for simply tracking redirect paths, suggesting potential overreach in data collection capabilities.

Recommendations:

Given the critical risk level, consider running this extension in a separate Chrome profile dedicated to SEO/marketing work to isolate it from personal browsing. Before installation, verify that Ayima UK Ltd is indeed the legitimate developer and check their privacy policy regarding data collection. Monitor the extension's behavior using Chrome's developer tools to ensure it's only accessing redirect-related data. Consider alternative redirect tracking tools with more limited permissions, or use browser developer tools' network tab for occasional redirect analysis instead of a persistent extension with such broad access.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: clipboardWrite
This extension has the clipboardWrite permission. Can modify clipboard content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.