CRX aminer

Starting analysis...

Extension icon

Popup Blocker - Blocks annoying Popups

Version 1.0.17 View in Chrome Web Store

Last scanned: 5 months ago | force re-scan

Extension Details

Developer: popupsblocker.org
Rating: 3.9 ★ (87 ratings)
Users: 100,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a moderate user base of 100,000 users and a decent rating of 3.9/5, suggesting some level of user acceptance. However, the relatively low number of reviews (87) compared to the user count raises questions about engagement authenticity. The developer domain "popupsblocker.org" appears purpose-built for this extension, but lacks established company reputation or transparency about the development team.

Concerns:

The extension requests extremely broad permissions that far exceed what's necessary for basic popup blocking. The combination of tabs permission, broad host permissions (<all_urls>), and content script injection across all websites creates a powerful surveillance capability. Most legitimate popup blockers operate through declarativeNetRequest rules without needing such extensive access. The unlimitedStorage permission is particularly concerning as it could enable large-scale data collection. The broad content script injection capability means this extension can read all data on every website you visit, including passwords, personal information, and financial data.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to non-sensitive browsing if you must use it. Better alternatives would be established popup blockers with more limited permissions, or using Chrome's built-in popup blocking features. If keeping this extension, regularly audit what data it might be collecting and avoid using it while accessing sensitive websites like banking or email services.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.