CRX aminer
Extension icon

Tabify

Version 1.5.0 View in Chrome Web Store

Last scanned: about 9 hours ago

Extension Details

Developer: tabify.dev
Rating: 5.0 ★ (2 ratings)
Users: 121

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has extremely limited trust indicators with only 121 users and just 2 ratings, making it difficult to assess community validation. The developer domain "tabify.dev" appears legitimate but lacks established reputation. The 5.0 rating is based on too few reviews to be meaningful. The extension's name suggests tab management functionality, but the excessive permissions far exceed what would be necessary for basic tab organization.

Concerns:

The permission set is extraordinarily broad and concerning for a tab management tool. The extension requests access to highly sensitive data including browsing history, cookies, bookmarks, downloads, and identity information. The management permission allows control over other extensions, creating potential for system-wide compromise. Host permissions for all URLs combined with webNavigation tracking enables comprehensive surveillance of user activity. The identity permission is particularly alarming as it can access authentication tokens. Many of these permissions appear completely unnecessary for tab management functionality.

Recommendations:

Do not install this extension in your primary browser profile due to the critical risk level. If you must test it, create an isolated Chrome profile with no sensitive data, bookmarks, or saved passwords. Consider alternative tab management extensions with more reasonable permission requests. The permission scope suggests potential malware or data harvesting rather than legitimate tab management. Wait for the extension to gain more users and reviews before considering installation, or contact the developer to justify the extensive permission requirements.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: bookmarks
This extension has the bookmarks permission. Can access and modify bookmarks. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: history
This extension has the history permission. Can access your browsing history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.