CRX aminer
Extension icon

Rewards Search Automator

Version 1.6.3 View in Chrome Web Store

Last scanned: about 1 month ago | force re-scan

Extension Details

Developer: buildwithkt.dev
Rating: 3.7 ★ (765 ratings)
Users: 100,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a substantial user base of 100,000 users, which suggests some level of community adoption. However, the moderate rating of 3.7 out of 5 from 765 reviews indicates mixed user experiences and potential issues. The developer "buildwithkt.dev" appears to be an individual developer rather than an established company, which reduces institutional trust. The extension's purpose of automating reward searches is legitimate but raises questions about compliance with reward program terms of service.

Concerns:

The extension requests an extremely broad and invasive set of permissions that far exceed what would be necessary for basic search automation. The debugger permission is particularly concerning as it allows manipulation of other extensions and browser debugging capabilities. The combination of browsing history access, web navigation tracking, and broad host permissions creates a comprehensive surveillance capability. The ability to inject content scripts into all websites poses significant security risks for credential theft and data harvesting. These permissions collectively enable the extension to monitor, record, and potentially manipulate virtually all browser activity.

Recommendations:

Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile with no saved passwords, personal data, or access to sensitive websites. Consider alternative reward automation tools with more limited permissions. Regularly review what data the extension might be collecting and consider the potential violation of reward program terms of service that could result in account suspension.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: debugger
This extension has the debugger permission. Can debug and manipulate other extensions/apps. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: history
This extension has the history permission. Can access your browsing history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.