CRX aminer
Extension icon

Fake Filler

Version 4.1.0 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Developer: fakefiller.com
Rating: 4.4 ★ (789 ratings)
Users: 400,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a solid user base of 400,000 users and maintains a good rating of 4.4 stars from 789 reviews, indicating general user satisfaction. The developer operates under a dedicated domain (fakefiller.com) which suggests some level of commitment to the product. The extension's purpose - filling forms with fake data for testing - is legitimate and commonly needed by developers and testers.

Concerns:

The primary concern is the broad content script injection capability across all URLs, which grants extensive access to read and modify any website content. While the contextMenus, activeTab, and storage permissions are reasonable for a form-filling tool, the combination with universal script injection creates potential for data harvesting or credential theft. The extension could theoretically capture sensitive information from banking sites, email platforms, or other confidential web applications, even though this may not be its intended purpose.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to development and testing activities, keeping it isolated from your primary browsing profile where you access sensitive accounts. Only enable the extension when actively needed for form testing. Regularly review what data the extension might be storing locally. If you frequently work with sensitive or production websites, consider using alternative form-filling methods that don't require such broad permissions, or temporarily disable the extension when not actively testing forms.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.