CRX aminer

Starting analysis...

Extension icon

Top and Bottom scroll buttons

Version 2.0.0 View in Chrome Web Store

Last scanned: 21 days ago | force re-scan

Extension Details

Rating: 4.5 ★ (43 ratings)
Users: 7,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a reasonable user base of 7,000 users with a solid 4.5-star rating from 43 reviews, suggesting it generally works as intended. However, the lack of developer information and company details reduces transparency and accountability.
Concerns: The extension's permissions are significantly excessive for its stated purpose of adding scroll buttons. The <all_urls> host permissions and content script injection capabilities allow it to access and modify content on every website you visit, which is unnecessary for simple scroll functionality. This creates potential for data harvesting, credential theft, or malicious content injection. The storage permission, while lower risk, adds another data collection vector. The broad permissions combined with limited developer transparency raises red flags about the extension's true intentions.
Recommendations: Given the high risk level, consider running this extension in a separate Chrome profile to isolate it from your main browsing activities and sensitive accounts. Alternatively, look for scroll button extensions from more established developers with narrower permissions, or use browser-native scroll shortcuts (Home/End keys, Page Up/Down). If you must use this extension, avoid using it while accessing banking, email, or other sensitive websites. Regularly review what data the extension might be storing and consider the trade-off between convenience and privacy.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.