CRX aminer
Extension icon

Folio: Manage Real Estate Deals from Gmail

Version 1.2.49608 View in Chrome Web Store

Last scanned: about 7 hours ago

Extension Details

Developer: Inside Real Estate, LLC
Rating: 4.7 ★ (212 ratings)
Users: 40,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a solid user base of 40,000 users and maintains a strong 4.7-star rating from 212 reviews, indicating positive user experiences. It's developed by Inside Real Estate, LLC, which appears to be a legitimate company in the real estate technology sector. The specific focus on real estate deal management from Gmail suggests a targeted, professional use case rather than a generic utility.

Concerns:

The cookies permission is particularly concerning as it allows the extension to access and modify browser cookies across permitted domains, which could compromise user privacy and security. The broad host permissions, while limited to specific domains (Gmail, Google APIs, and Amitree), still provide significant access to sensitive email data and external services. The storage permission, though less critical, allows local data retention that users should be aware of. The extension's access to Gmail content through content scripts means it can read and potentially process all email communications.

Recommendations:

Consider running this extension in a dedicated Chrome profile used specifically for real estate work to isolate it from personal browsing. Regularly review what data the extension might be storing locally and ensure your Gmail account has appropriate security measures enabled. Monitor the extension's behavior and disable it when not actively managing real estate deals. Given the legitimate business use case and positive user feedback, the risk may be acceptable for real estate professionals who need this functionality, but personal users should exercise caution.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://apis.google.com/, https://mail.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.