CRX aminer
Extension icon

硬是要縮

Version 1.0 View in Chrome Web Store

Last scanned: about 8 hours ago

Extension Details

Developer: 4fun.tw
Rating: 4.0 ★ (6 ratings)
Users: 311

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has very limited user adoption with only 311 users and minimal review data (6 ratings). The name "硬是要縮" appears to be in Chinese and suggests URL shortening functionality. The developer 4fun.tw lacks established reputation or detailed information, making it difficult to verify legitimacy. The extension hasn't been updated recently and uses outdated manifest version 2.

Concerns:

The tabs permission is particularly concerning for a URL shortening tool, as it grants broad access to browse all open tabs, view URLs, and manipulate tab behavior - capabilities that far exceed what's needed for basic URL shortening. The combination of tabs permission with broad host permissions (http://*/*, https://*/*) creates significant privacy and security risks. The extension could potentially monitor browsing activity, access sensitive information across all websites, or redirect users to malicious sites. The outdated Manifest V2 provides fewer security protections compared to modern extensions.

Recommendations:

Consider running this extension in a separate Chrome profile to isolate potential risks from your main browsing environment. Look for alternative URL shortening tools from established developers with better security practices and Manifest V3 compliance. If you must use this extension, regularly monitor your browsing behavior for any unusual redirects or performance issues, and consider removing it after use rather than keeping it permanently installed.

Findings

HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.