CRX aminer
Extension icon

100xWorkflows

Version 1.7.14 View in Chrome Web Store

Last scanned: about 7 hours ago

Extension Details

Developer: 100x.bot
Rating: 4.8 ★ (15 ratings)
Users: 1,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a relatively small user base of only 1,000 users, which limits community validation. While it maintains a high rating of 4.8 stars, this is based on only 15 reviews, making the sample size too small to be statistically meaningful. The developer "100x.bot" lacks established reputation or transparency about their identity and business practices. The missing description raises additional concerns about the extension's intended functionality.

Concerns:

The extension requests an extremely broad set of permissions that far exceed what most legitimate productivity tools require. The combination of desktopCapture, tabCapture, and scripting permissions alongside universal website access creates a powerful surveillance toolkit. The identity permission combined with broad host permissions could enable account hijacking or credential theft. The power permission suggests system-level access that's rarely necessary for browser extensions. The absence of a clear description makes it impossible to verify if these permissions align with legitimate functionality.

Recommendations:

Do not install this extension due to its critical risk level. If you must use it, create an isolated Chrome profile with no saved passwords, personal data, or access to sensitive websites. Consider using a virtual machine for additional isolation. Monitor your accounts for unauthorized access if you've previously used this extension. Look for alternative workflow automation tools from established developers with transparent privacy policies and more reasonable permission requests.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: <all_urls>
This extension has the <all_urls> permission. Can access all websites and their content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.