CRX aminer
Extension icon

Smart Web Paint for Chrome

Version 1.8.7 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Developer: web-paint-smart.com
Rating: 4.3 ★ (31 ratings)
Users: 20,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a moderate user base of 20,000 users and maintains a solid 4.3-star rating from 31 reviews, indicating generally positive user experiences. However, the limited number of reviews relative to the user count suggests many users haven't provided feedback. The developer domain web-paint-smart.com appears to be purpose-built for this extension, but lacks established company reputation or transparency about the development team.

Concerns:

The primary concern is the broad host permissions (<all_urls>) which grants the extension access to all websites you visit. For a web painting tool, this level of access seems excessive and creates potential privacy risks. The combination of storage permissions with universal website access means the extension could theoretically collect and store data from any site you visit. The scripting permission, while necessary for the extension's functionality, combined with broad host access amplifies the potential for misuse.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to web annotation tasks to limit exposure of your primary browsing data. Before installing, verify that the functionality truly requires access to all websites rather than just specific ones where you plan to use the painting features. Monitor the extension's behavior and consider alternatives that request more limited permissions if available. Regularly review what data the extension might be storing locally through Chrome's extension management settings.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.