CRX aminer
Extension icon

Opt Out - send GDPR and CCPA data requests

Version 2.0 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Developer: yourdigitalrights.org
Rating: 5.0 ★ (6 ratings)
Users: 707

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension comes from yourdigitalrights.org, which appears to be a legitimate organization focused on digital privacy rights. The 5.0 rating from 6 reviews suggests positive user experiences, though the small sample size limits reliability. The extension's purpose - helping users send GDPR and CCPA data requests - aligns with legitimate privacy advocacy. However, the very low user count of 707 indicates limited adoption and testing in the wild.

Concerns:

The tabs permission is overly broad for an extension that should primarily facilitate data requests. This permission allows access to all browser tab information, which seems unnecessary for the stated functionality. The extension uses the older Manifest V2, which has weaker security protections compared to V3. The limited user base and lack of recent update information raise questions about ongoing maintenance and security patches.

Recommendations:

Consider running this extension in a separate Chrome profile to isolate potential risks from your main browsing activities. Before installation, verify the legitimacy of yourdigitalrights.org and their privacy practices. Monitor the extension's behavior and disable it when not actively needed for data requests. Look for alternative extensions with similar functionality that use Manifest V3 and have more restrictive permissions. Given the specialized nature of GDPR/CCPA requests, you might also consider using the organization's website directly instead of the extension.

Findings

HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.