CRX aminer
Extension icon

TextUs Next Extension (Legacy)

Version 4.0.41 View in Chrome Web Store

Last scanned: about 21 hours ago

Extension Details

Rating: 3.0 ★ (57 ratings)
Users: 9,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension appears to be a legitimate business communication tool for TextUs, a professional texting platform commonly used in recruiting and staffing. With 9,000 users and integration with established platforms like Salesforce, Bullhorn, and Dynamics, it shows signs of legitimate business use. However, the 3.0 rating from 57 reviews suggests mixed user experiences, and the "Legacy" designation indicates this may be an outdated version.

Concerns:

The most significant concern is the overly broad host permissions (http://*/*, https://*/*) which grant access to all websites, far exceeding what's necessary for a business texting tool. The tabs permission allows manipulation of browser tabs, which combined with universal website access creates privacy risks. The extension can inject content scripts across numerous domains including localhost, suggesting development/testing remnants that shouldn't be in production. Using Manifest V2 indicates outdated security standards, and the lack of recent update information raises maintenance concerns.

Recommendations:

Consider running this extension in a separate Chrome profile to isolate its broad permissions from your primary browsing. Verify with your organization that this legacy version is still officially supported, as newer, more secure versions may be available. Monitor the extension's behavior closely and consider alternatives if available. If you must use it, limit browsing sensitive websites while the extension is active, and regularly review what data it may be accessing through its extensive permissions.

Findings

HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.