CRX aminer
Extension icon

Sendr - Hyper-personalized outreach at scale

Version 1.1.5 View in Chrome Web Store

Last scanned: about 18 hours ago

Extension Details

Developer: Intro Labs LTD
Rating: 4.8 ★ (6 ratings)
Users: 1,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: The extension has a very small user base of only 1,000 users and just 6 reviews, making it difficult to assess reliability through community feedback. While it maintains a high 4.8-star rating, the limited sample size reduces confidence in this metric. The developer, Intro Labs LTD, lacks established reputation indicators in the extension ecosystem.
Concerns: This extension exhibits extremely broad access capabilities that far exceed what would be necessary for typical outreach automation. The combination of cookies permission with universal host access creates significant privacy risks, as it can read and modify authentication data across all websites. The ability to inject content scripts into every website visited, coupled with tab manipulation permissions, creates potential for credential harvesting, session hijacking, and unauthorized data collection. The broad permissions suggest the extension could monitor all browsing activity and potentially exfiltrate sensitive business communications or personal data.
Recommendations: Given the critical risk level, avoid installing this extension on your primary browser profile. If the functionality is essential for your business, create an isolated Chrome profile specifically for this extension and limit its use to only necessary websites. Consider alternative outreach tools with more restrictive permissions. Regularly audit what data the extension might be accessing and ensure your organization's security policies permit such broad access tools. Monitor for any unusual network activity or unauthorized account access after installation.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.