CRX aminer
Extension icon

Frame By Frame

Version 3.5 View in Chrome Web Store

Last scanned: 4 months ago | force re-scan

Extension Details

Rating: 3.8 ★ (36 ratings)
Users: 10,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a modest user base of 10,000 users with a moderate rating of 3.8/5 from 36 reviews. However, several trust indicators are missing including author information, developer details, and last update date, which raises transparency concerns. The lack of developer information makes it difficult to assess the publisher's credibility and track record.

Concerns:

The extension's broad permissions are disproportionate to its apparent functionality as a frame-by-frame video tool. The <all_urls> host permissions and content script injection capabilities allow it to access and modify any website you visit, including sensitive sites like banking or email platforms. This creates significant potential for data theft, credential harvesting, or unauthorized tracking. The storage permission, while less concerning individually, could be used to persist stolen data or tracking information across sessions.

Recommendations:

Given the high risk level, consider running this extension in a separate Chrome profile dedicated to video-related tasks only. Avoid using this profile for sensitive activities like banking, shopping, or accessing personal accounts. Before installation, verify if similar functionality is available through browser-native features or extensions with more limited permissions. If you must use this extension, regularly review your browser's security settings and consider using additional privacy protection measures. Monitor for any unusual browser behavior or unexpected network activity after installation.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.