CRX aminer
Extension icon

APKHUB App Downloder

Version 1.0.1 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Developer: pgyer.com
Rating: 4.4 ★ (13 ratings)
Users: 3,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a relatively small user base of 3,000 users with a decent rating of 4.4 stars, though based on only 13 reviews which is quite limited. The developer is associated with pgyer.com, which appears to be a legitimate app distribution platform. However, the extension name contains a typo ("Downloder" instead of "Downloader"), which raises questions about quality control and attention to detail.

Concerns:

The most significant concern is the broad content script injection capability that allows the extension to run scripts on all websites you visit. This creates substantial privacy and security risks as it can potentially access sensitive information like passwords, personal data, or financial information on any site. The combination of activeTab permission with all_urls content scripts is particularly concerning, as it provides extensive access to web content. While the individual permissions (contextMenus, activeTab, storage) are reasonable for an app downloader, the broad injection capability seems excessive for the stated purpose.

Recommendations:

Given the high-risk content script injection, consider running this extension in a separate Chrome profile to isolate it from your primary browsing activities. Monitor the extension's behavior closely and be cautious when visiting sensitive websites while it's active. Consider whether the functionality truly requires such broad access, and look for alternative extensions with more limited permissions if available.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.