CRX aminer
Extension icon

Tackle

Version 9.24.0 View in Chrome Web Store

Last scanned: 2 months ago | force re-scan

Extension Details

Developer: TimeTackle Inc
Rating: 4.5 ★ (24 ratings)
Users: 2,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a solid 4.5-star rating from 24 reviews and is developed by TimeTackle Inc, suggesting legitimate business backing. However, the relatively low user count of 2,000 users indicates limited adoption, which could mean less community vetting. The extension appears to be a time tracking tool that integrates with Google Calendar based on its permissions and host access patterns.

Concerns:

The primary concern is the broad host permissions that allow access to multiple domains including the developer's own app domains and Google Calendar. While the Google Calendar access aligns with the extension's apparent time tracking functionality, the combination of activeTab permission with broad host access creates potential for data collection beyond what's necessary. The storage permission, while common, adds to the data handling capabilities. The extension can inject content scripts into Google Calendar pages, which could potentially access sensitive calendar information.

Recommendations:

Given the medium risk level, consider running this extension in a separate Chrome profile if you handle highly sensitive information in your browser. Before installation, verify that TimeTackle Inc is a legitimate company and review their privacy policy to understand data handling practices. Monitor the extension's behavior after installation and revoke permissions if you notice unexpected activity. Consider whether the time tracking functionality justifies the broad access permissions requested.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://calendar.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.