CRX aminer
Extension icon

Nudge Security Browser Extension

Version 0.10.137 View in Chrome Web Store

Last scanned: 4 days ago | force re-scan

Extension Details

Developer: nudgesecurity.com
Rating: 5.0 ★ (1 rating)
Users: 90,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension comes from nudgesecurity.com, which appears to be a legitimate security company. With 90,000 users and a perfect 5.0 rating, it shows some adoption, though the single review count raises questions about the rating's reliability. The company appears to focus on security solutions, which provides some context for the extensive permissions.

Concerns:

The extension requests an extremely broad set of permissions that far exceed what most legitimate extensions require. The combination of management permissions (can control other extensions), webRequest interception, clipboard access, identity information, and universal host permissions creates a perfect storm for potential abuse. The content script injection across numerous AI platforms and email services (Gmail, Outlook) suggests comprehensive monitoring capabilities. The geolocation permission seems unnecessary for a security tool, and the ability to access downloads and web navigation history provides extensive tracking capabilities.

Most concerning is the <all_urls> permission appearing multiple times, granting unrestricted access to every website you visit. For a security extension, this level of access could be justified but requires absolute trust in the vendor.

Recommendations:

Given the critical risk level, run this extension in a completely separate Chrome profile dedicated solely to security monitoring if you must use it. Never use this profile for personal browsing, banking, or sensitive activities. Verify the extension's legitimacy directly with Nudge Security before installation. Consider whether the security benefits truly justify such extensive system access. Monitor your system closely for any unusual activity after installation.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: clipboardRead
This extension has the clipboardRead permission. Can read clipboard content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: geolocation
This extension has the geolocation permission. Can access your location.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.