CRX aminer
Extension icon

Agent Risk Reminder Remover - CNFans, ACBuy & More

Version 1.0.1 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Rating: 5.0 ★ (8 ratings)
Users: 549

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a perfect 5.0 rating but only 8 reviews, which is insufficient to establish credibility. With only 549 users, it has very limited adoption. The lack of developer information and company details raises transparency concerns. The extension targets Chinese shopping agent websites, which may involve financial transactions and personal data.

Concerns:

The extension requests access to an unusually broad range of domains (40+ shopping agent sites plus Reddit, Google Docs/Sheets, and Yupoo), which far exceeds what would be necessary for simply removing risk reminders. The tabs permission allows monitoring and manipulation of all browser tabs, not just the targeted shopping sites. The notifications and storage permissions, while individually reasonable, combined with the extensive host permissions create a concerning attack surface. The extension could potentially intercept sensitive shopping data, payment information, or personal communications across multiple platforms.

Recommendations:

Given the high risk level, install this extension only in a separate Chrome profile dedicated to shopping agent activities. Regularly review the extension's behavior and remove it when not actively needed. Consider whether the convenience of removing risk reminders justifies the extensive permissions granted. Monitor your accounts on the affected shopping platforms for any unusual activity. If possible, use alternative methods to manage risk warnings rather than relying on this extension.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://docs.google.com/*, https://sheets.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.