CRX aminer
Extension icon

Foxtrick (Beta)

Version 0.17.9.2857 View in Chrome Web Store

Last scanned: about 9 hours ago

Extension Details

Developer: foxtrick.org
Rating: 5.0 ★ (9 ratings)
Users: 9,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a perfect 5.0 rating but with only 9 reviews, making the sample size too small for reliable assessment. With 9,000 users, it has moderate adoption but lacks transparency regarding the developer's identity and company reputation. The foxtrick.org domain suggests it's related to the Hattrick online football management game, which provides some context for its purpose.
Concerns: The extension requests several high-risk permissions that could be concerning. The cookies permission allows access to sensitive authentication data across multiple Hattrick domains, while clipboardWrite could potentially inject malicious content. The broad host permissions across numerous Hattrick-related domains (*://*.hattrick.org/*, *://*.hattrick.ws/*, etc.) create an extensive attack surface. The use of Manifest V2 provides fewer security protections compared to V3. The combination of cookie access and clipboard modification capabilities presents privacy and security risks if the extension were compromised.
Recommendations: Given the high-risk permissions, consider running this extension in a separate Chrome profile dedicated to Hattrick gaming activities. Verify the extension's legitimacy by checking if it's officially endorsed by Hattrick or the gaming community. Monitor your clipboard content after using the extension and be cautious about sensitive information. Consider whether all the requested permissions are necessary for the extension's stated functionality, and look for alternative extensions with more limited permission requests if available.

Findings

HIGH
High-Risk Permission: clipboardWrite
This extension has the clipboardWrite permission. Can modify clipboard content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.