The extension has a moderate user base of 9,000 users but concerning trust indicators. The 3.0 rating from only 41 reviews suggests limited user engagement or potential dissatisfaction. The developer "sehasolutions.com" appears to be a legitimate business entity, which provides some credibility. However, the lack of detailed developer information and recent update history raises questions about ongoing support and transparency.
The extension's broad host permissions are particularly concerning, granting access to major professional networking sites (LinkedIn, Xing), GitHub, and multiple Vincere API endpoints. The tabs permission combined with these extensive host permissions creates significant privacy risks, as the extension can monitor and manipulate browsing activity across these platforms. The storage permission allows data collection and retention, while the scripting permission enables code injection into visited pages. The specific focus on professional networking and recruitment platforms suggests this may be a data harvesting tool for business purposes.
Given the high risk level, consider running this extension in a separate Chrome profile dedicated to professional activities only. Carefully review what data the extension collects and how it's used before installation. Monitor your account activities on LinkedIn and other accessed platforms for any unusual behavior. Consider whether the extension's functionality justifies the extensive permissions requested. If you must use it, regularly audit the extension's behavior and remove it if you notice any suspicious activity.
| https://clients2.google.com/service/update2/crx | http://github.com/ | |
| https://github.com/ | https://id.vincere.io/oauth2/hello | |
| https://id-qa.vincere.io/oauth2/hello | https://id-stag.vincere.io/oauth2/hello | |
| https://static.sehasolutions.com/ | https://www.linkedin.com/in/johndoe/ | |
| https://johndoe.dev | https://www.linkedin.com/in/janesmith/ | |
| https://janesmith.com | https://static.licdn.com/sc/h/djzv59yelk5urv2ujlazfyvrk | |
| https://id.vincere.io/oauth2/v2/token | https://id.vincere.io/oauth2/v2/authorize | |
| https://id.vincere.io/oauth2/logout | https://id.vincere.io/oauth2/user | |
| https://24fd7db346524e95bc1b3d3ff3ffb164@sentry.io/1279280 | http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd | |
| http://www.w3.org/2000/svg | http://www.w3.org/1999/xhtml | |
| https://fonts.googleapis.com/css?family=Open+Sans:400 | http://www.w3.org/1999/xlink | |
| https://static-exp1.licdn.com/sc/h/244xhbkr7g40x6bsu4gi6q4ry | https://sb-test.vinceredev.com/api/v2 | |
| http://www.example.com | https://docs.sentry.io/platforms/javascript/best-practices/browser-extensions/ | |
| http://linkedin.com/ | https://linkedin.com/ | |
| http://www.linkedin.com/ | https://www.linkedin.com/ | |
| https://getbootstrap.com/ | https://github.com/twbs/bootstrap/blob/master/LICENSE | |
| https://github.com/h5bp/html5-boilerplate/blob/master/src/css/main.css | http://jqueryui.com | |
| http://jquery.org/license | http://api.jqueryui.com/jQuery.widget/ | |
| http://jqueryui.com/widget/ | http://api.jqueryui.com/position/ | |
| http://jqueryui.com/position/ | http://api.jqueryui.com/data-selector/ | |
| http://api.jqueryui.com/disableSelection/ | http://api.jqueryui.com/category/effects-core/ | |
| http://jqueryui.com/effect/ | https://github.com/jquery/jquery-color | |
| https://code.google.com/p/maashaack/source/browse/packages/graphics/trunk/src/graphics/colors/HUE2RGB.as?r=5021 | https://bugzilla.mozilla.org/show_bug.cgi?id=561664 | |
| http://jsfiddle.net/JZSMt/3/ | https://bugs.webkit.org/show_bug.cgi?id=107380 | |
| http://www.robertpenner.com/easing | http://api.jqueryui.com/blind-effect/ | |
| http://api.jqueryui.com/bounce-effect/ | http://api.jqueryui.com/clip-effect/ | |
| http://api.jqueryui.com/drop-effect/ | http://api.jqueryui.com/explode-effect/ | |
| http://api.jqueryui.com/fade-effect/ | http://api.jqueryui.com/fold-effect/ | |
| http://api.jqueryui.com/highlight-effect/ | http://api.jqueryui.com/size-effect/ | |
| http://api.jqueryui.com/scale-effect/ | http://api.jqueryui.com/puff-effect/ | |
| http://api.jqueryui.com/pulsate-effect/ | http://api.jqueryui.com/shake-effect/ | |
| http://api.jqueryui.com/slide-effect/ | http://api.jqueryui.com/transfer-effect/ | |
| http://api.jqueryui.com/focusable-selector/ | http://api.jqueryui.com/form-reset-mixin/ | |
| http://api.jqueryui.com/jQuery.ui.keyCode/ | http://api.jqueryui.com/labels/ | |
| http://api.jqueryui.com/scrollParent/ | http://api.jqueryui.com/tabbable-selector/ | |
| http://api.jqueryui.com/uniqueId/ | http://api.jqueryui.com/accordion/ | |
| http://jqueryui.com/accordion/ | http://api.jqueryui.com/menu/ | |
| http://jqueryui.com/menu/ | http://api.jqueryui.com/autocomplete/ | |
| http://jqueryui.com/autocomplete/ | https://code.google.com/p/chromium/issues/detail?id=313082 | |
| http://api.jqueryui.com/controlgroup/ | http://jqueryui.com/controlgroup/ |
{ "name": "__MSG_extName__", "icons": { "16": "images/logo-16.png", "48": "images/logo-48.png", "128": "images/logo-128.png" }, "action": { "default_icon": "images/logo-128.png", "default_popup": "html/popup.html", "default_title": "__MSG_ext_default_title__" }, "version": "4.0.0", "background": { "service_worker": "service_worker/service_worker.min.js" }, "short_name": "__MSG_extName__", "side_panel": { "default_path": "html/sidepanel.html" }, "update_url": "https://clients2.google.com/service/update2/crx", "description": "__MSG_extDescription__", "permissions": [ "scripting", "tabs", "storage", "activeTab", "contextMenus", "sidePanel" ], "default_locale": "en", "content_scripts": [ { "js": [ "vendor/jquery-2.1.1.min.js", "vendor/jquery.i18n/libs/CLDRPluralRuleParser/CLDRPluralRuleParser.js", "vendor/jquery.i18n/jquery.i18n.js", "vendor/jquery.i18n/jquery.i18n.messagestore.js", "vendor/jquery.i18n/jquery.i18n.fallbacks.js", "vendor/jquery.i18n/jquery.i18n.parser.js", "vendor/jquery.i18n/jquery.i18n.emitter.js", "vendor/jquery.i18n/jquery.i18n.language.js", "vendor/jquery-ui-v1.12.1.js", "vendor/jquery.validate.js", "vendor/jquery.validate.unobtrusive.min.js", "vendor/sha256.min.js", "vendor/select2/js/select2.full.min.js", "vendor/libphonenumber/libphonenumber-js.min.js", "vendor/moment.min.js", "vendor/ladda.js", "js/translate.min.js", "js/tracking.min.js", "js/foreground.min.js", "js/generateCode.min.js" ], "css": [ "vendor/fontawesome/css/font-awesome.min.css", "vendor/select2/css/select2.css", "vendor/ladda/dist/ladda-themeless.min.css", "vendor/jquery-ui.css", "styles/vite/main.css", "styles/vite/form.css" ], "run_at": "document_end", "matches": [ "http://*.linkedin.com/*", "https://*.linkedin.com/*", "http://*.xing.com/*", "https://*.xing.com/*", "http://github.com/*", "https://github.com/*" ] }, { "js": [ "oauth2/injection.min.js" ], "run_at": "document_start", "matches": [ "https://*.vinceredev.com/oauth2/hello*", "https://id.vincere.io/oauth2/hello*", "https://id-qa.vincere.io/oauth2/hello*", "https://id-stag.vincere.io/oauth2/hello*" ] } ], "host_permissions": [ "http://*.linkedin.com/*/*", "https://*.linkedin.com/*/*", "http://*.xing.com/*/*", "https://*.xing.com/*/*", "http://github.com/*", "https://github.com/*", "https://*.vincere.io/api/v2/*/*", "https://*.vinceredev.com/api/v2/*/*", "https://static.sehasolutions.com/*" ], "manifest_version": 3, "content_security_policy": { "extension_pages": "script-src 'self'; object-src 'self'" }, "web_accessible_resources": [ { "matches": [ "<all_urls>" ], "resources": [ "oauth2/*", "fonts/*", "env/*", "vendor/*", "images/*", "js/*", "backend/*", "i18n/*", "html/*" ] } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.