CRX aminer

Starting analysis...

Extension icon

COACH by Dropzone AI

Version 0.8.5 View in Chrome Web Store

Last scanned: 4 months ago | force re-scan

Extension Details

Rating: 5.0 ★ (7 ratings)
Users: 654

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a perfect 5.0 rating but with only 7 reviews, which is a very small sample size. With just 654 users, this is a relatively new or niche extension. The lack of visible developer information and company details reduces transparency. The "Dropzone AI" branding suggests an AI-powered coaching tool, but without more context about the company's reputation, trust assessment is limited.

Concerns:

The extension requests access to a specific AWS API endpoint (execute-api.us-west-2.amazonaws.com), which suggests it's sending data to external servers for processing. This raises privacy concerns about what data is being transmitted and how it's handled. The combination of storage and activeTab permissions means the extension can both access your current webpage content and store that information locally. The scripting permission allows code injection into web pages, which could potentially be misused.

Recommendations:

Given the medium risk level and limited user base, consider running this extension in a separate Chrome profile to isolate it from your main browsing activities. Before installing, research Dropzone AI's privacy policy and data handling practices. Monitor what data the extension accesses by checking Chrome's extension activity logs. If you proceed with installation, regularly review the extension's behavior and consider removing it if you notice unexpected activity or if your trust level decreases.

Findings

MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://gr1yg059sf.execute-api.us-west-2.amazonaws.com/ajr/dz/coach. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.