CRX aminer
Extension icon

Top and Bottom scroll buttons

Version 2.0.0 View in Chrome Web Store

Last scanned: 4 months ago | force re-scan

Extension Details

Rating: 4.5 ★ (41 ratings)
Users: 5,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a decent user base of 5,000 users and a good rating of 4.5 stars from 41 reviews, suggesting users find it functional. However, the lack of developer information and company details reduces transparency and accountability.
Concerns: The extension's permissions are severely excessive for its stated purpose of providing scroll buttons. The <all_urls> host permissions and content script injection capabilities allow it to access and modify every website you visit, which is completely unnecessary for adding simple scroll functionality. This creates significant privacy and security risks, as the extension could potentially steal sensitive data, track browsing activity, or inject malicious content across all websites.

The storage permission, while less concerning, allows the extension to store data locally, which could be used to maintain persistent tracking information.

Recommendations: Given the disproportionate permissions relative to functionality, consider using this extension in a separate Chrome profile dedicated to non-sensitive browsing activities. Alternatively, look for similar scroll enhancement extensions that request more appropriate, limited permissions. Before using, carefully review what data the extension might access and consider whether the convenience of scroll buttons justifies the broad access to all your web activity. Monitor the extension's behavior and remove it immediately if you notice any suspicious activity or unexpected data usage.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.