CRX aminer
Extension icon

יואל גבע

Version 3.1 View in Chrome Web Store

Last scanned: about 15 hours ago

Extension Details

Rating: 4.1 ★ (41 ratings)
Users: 2,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a modest user base of 2,000 users with a decent rating of 4.1 stars from 41 reviews, suggesting some level of user satisfaction. However, several trust factors are concerning: the extension name appears to be in Hebrew (יואל גבע), but there's no clear description of what the extension does, no author information provided, and no developer details available. The lack of transparency about the extension's purpose and creator significantly reduces trustworthiness.

Concerns:

The most significant concern is the overly broad permissions for an extension with an unclear purpose. The combination of http://*/* and https://*/* permissions with content script injection means this extension can access and modify content on every website you visit. The storage and unlimitedStorage permissions allow it to store unlimited data locally, which could be used to collect and retain browsing information. The use of Manifest V2 indicates outdated security standards. The complete absence of a meaningful description makes it impossible to determine if these extensive permissions are justified.

Recommendations:

Given the broad permissions and lack of transparency, consider running this extension in a separate Chrome profile if you must use it. Better yet, try to identify what specific functionality you need and find a more transparent alternative. Contact the developer for clarification about the extension's purpose before continued use. Monitor your browsing behavior for any unusual activity while this extension is active.

Findings

MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.