CRX aminer
Extension icon

MCAT.tools Companion

Version 1.0.0.315 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Developer: mcat.tools
Rating: 5.0 ★ (1 rating)
Users: 332

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has very limited adoption with only 332 users and a single 5-star rating, making it difficult to assess reliability through community feedback. The developer "mcat.tools" appears to be associated with MCAT preparation tools, which provides some context for the extension's purpose. However, the lack of detailed developer information and minimal user base raises concerns about accountability and transparency.

Concerns:

The extension requests extremely broad permissions that seem excessive for an MCAT study companion. The <all_urls> host permission allows access to every website you visit, while the cookies permission enables reading and modifying authentication data across all sites. The combination of these permissions creates significant privacy and security risks, as the extension could potentially track your browsing habits, access sensitive account information, or modify login credentials. The localhost permission suggests development/testing functionality that shouldn't be present in a production extension.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated solely to MCAT study activities to limit exposure. Before installation, contact the developer to understand why such broad permissions are necessary for MCAT preparation features. Monitor your browser's activity and consider using incognito mode when accessing sensitive sites. Given the high-risk permission combination and limited user base, you may want to explore alternative MCAT study tools with more restrictive permissions and established user communities.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.