CRX aminer
Extension icon

PayPal Honey: Automated Coupons & Cash Back

Version 19.0.1 View in Chrome Web Store

Last scanned: 6 days ago | force re-scan

Extension Details

Developer: https://www.joinhoney.com/
Rating: 4.6 ★ (179.8K ratings)
Users: 13,000,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors: PayPal Honey is a legitimate extension owned by PayPal, one of the world's largest payment companies. With 13 million users and a 4.6-star rating from nearly 180,000 reviews, it has established credibility. The extension's core functionality - finding coupons and providing cashback - is well-known and widely used by consumers.
Concerns: While the security findings flag several high-risk permissions, these are largely necessary for Honey's legitimate operations. The cookies permission allows it to maintain user sessions and apply discounts. The webRequest permission enables intercepting checkout processes to inject coupon codes. Broad host permissions are required since the extension works across thousands of shopping websites. However, these permissions do create a powerful surveillance capability that could theoretically track all browsing activity and intercept sensitive data.

The main privacy concern is that Honey collects extensive shopping data to power its business model, which involves affiliate commissions and data insights. Users should understand they're trading browsing privacy for savings.

Recommendations: This extension is generally safe for most users given PayPal's reputation and regulatory oversight. Privacy-conscious users might consider running it in a dedicated shopping browser profile to limit data collection to shopping activities only. Review Honey's privacy policy to understand data collection practices. The extension's benefits typically outweigh risks for casual shoppers, but users handling sensitive financial information professionally should exercise additional caution.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.