CRX aminer
Extension icon

Rakuten: Get Cash Back For Shopping

Version 26.10.0 View in Chrome Web Store

Last scanned: about 12 hours ago

Extension Details

Developer: http://rakuten.com/
Rating: 4.9 ★ (43.6K ratings)
Users: 3,000,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: Rakuten is a well-established, publicly traded e-commerce company with a legitimate cash-back business model. The extension has 3 million users and an excellent 4.9-star rating from over 43,000 reviews, indicating strong user satisfaction and reliability. The company's reputation and business model provide significant credibility.
Concerns: Despite the legitimate business purpose, this extension requires extensive permissions that create substantial privacy and security exposure. The combination of tabs, webNavigation, webRequest, and cookies permissions with broad host access (<all_urls>) means the extension can monitor all your browsing activity, intercept web requests, and access cookies across every website you visit. While necessary for detecting shopping opportunities and applying cash-back offers, these permissions far exceed what most users would expect from a shopping tool and create potential for comprehensive tracking.
Recommendations: Given Rakuten's legitimate business model and strong reputation, the risk is primarily privacy-related rather than malicious. However, users concerned about extensive tracking should consider running this extension in a dedicated Chrome profile used only for shopping activities. Alternatively, manually visit Rakuten's website before making purchases instead of using the extension. For users comfortable with comprehensive browsing tracking in exchange for cash-back rewards, the extension appears safe given the company's established reputation, but be aware that your complete browsing behavior will be monitored.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.