CRX aminer
Extension icon

DuoKeyboard

Version 1.5.1 View in Chrome Web Store

Last scanned: 1 day ago | force re-scan

Extension Details

Rating: 4.2 ★ (49 ratings)
Users: 5,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a modest user base of 5,000 users with a decent 4.2-star rating from 49 reviews, suggesting generally positive user experiences. However, the lack of visible developer information and company details reduces transparency and accountability. The extension appears to be specifically designed for Duolingo users, as evidenced by its content script targeting only Duolingo domains.

Concerns:

The primary concern is the tabs permission, which grants broad access to browser tab information and manipulation capabilities. This is excessive for what appears to be a keyboard enhancement tool for Duolingo. The extension could potentially monitor browsing activity across all tabs, access sensitive information from other websites, or manipulate tabs in unintended ways. While the storage permission is standard for extensions that need to save user preferences, the combination with tabs access creates elevated privacy risks.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to language learning to limit exposure to other browsing activities. Before installation, verify that the keyboard functionality truly requires tab-level permissions by testing similar extensions with more restrictive permissions. Monitor the extension's behavior and remove it if you notice any unexpected tab manipulation or performance issues. Given the limited developer transparency, stay alert for updates and user reviews that might indicate changes in behavior or security concerns.

Findings

HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.