CRX aminer
Extension icon

AIS Visa Auto Rescheduler

Version 4.1.0.0 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Rating: 4.4 ★ (310 ratings)
Users: 10,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a decent user base of 10,000 users and a solid 4.4-star rating from 310 reviews, suggesting legitimate functionality. The specific targeting of the US visa appointment system (ais.usvisa-info.com) indicates a specialized tool for a common need among visa applicants.
Concerns: The extension requests several powerful permissions that create significant security risks. The cookies permission combined with broad host access could allow unauthorized manipulation of authentication sessions. The scripting permission enables code injection capabilities on the visa website. The notifications and storage permissions, while less critical, add to the overall attack surface. Most concerning is that these permissions exceed what would typically be necessary for a simple appointment rescheduling tool.

The host permission is appropriately scoped to the specific visa website, which is positive, but the combination of cookies access and scripting capabilities on a sensitive government-related site raises privacy and security concerns.

Recommendations: Consider running this extension in a separate Chrome profile dedicated solely to visa-related activities. Before installation, verify the extension's legitimacy through official visa appointment forums or communities. Monitor your visa account for any unauthorized changes after use. Consider uninstalling the extension immediately after completing your rescheduling needs. Alternative manual methods for appointment rescheduling may be safer despite being less convenient.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.