CRX aminer
Extension icon

Chatgpt PDF | Ask your pdf

Version 1.4.1 View in Chrome Web Store

Last scanned: about 6 hours ago

Extension Details

Developer: pdfsummary.ai
Rating: 4.5 ★ (61 ratings)
Users: 10,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a moderate user base of 10,000 users and a solid 4.5-star rating from 61 reviews, which suggests reasonable user satisfaction. The developer pdfsummary.ai appears to be focused on PDF-related tools, which aligns with the extension's stated purpose. However, the relatively small number of reviews compared to the user count may indicate limited user engagement or feedback.

Concerns:

The most significant concern is the extension's extremely broad permissions that far exceed what would be necessary for a PDF interaction tool. The <all_urls> host permissions and content script injection capabilities allow this extension to access and modify content on every website you visit, not just PDF-related sites. This creates potential for data harvesting, credential theft, or unauthorized website modifications. For a tool supposedly focused on PDF analysis, these permissions are excessive and raise red flags about the extension's true capabilities and intentions.

Recommendations:

Given the high risk level, consider running this extension in a separate Chrome profile isolated from your main browsing activities. Before installation, carefully evaluate whether you truly need this functionality, as there may be safer alternatives for PDF analysis. If you proceed, monitor the extension's behavior closely and revoke permissions if you notice any suspicious activity. Consider using dedicated PDF analysis tools that don't require browser extensions instead.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.