CRX aminer

Starting analysis...

Extension icon

Tackle

Version 9.26.0 View in Chrome Web Store

Last scanned: 3 days ago | force re-scan

Extension Details

Developer: TimeTackle Inc
Rating: 4.5 ★ (24 ratings)
Users: 3,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension is developed by TimeTackle Inc, which appears to be a legitimate time tracking company based on the domain permissions and functionality. With 3,000 users and a solid 4.5-star rating from 24 reviews, it shows reasonable adoption and user satisfaction. The extension uses Manifest V3, indicating compliance with modern Chrome security standards. The version number (9.26.0) suggests active development and maintenance.

Concerns:

The primary concern is the broad host permissions that extend beyond what appears necessary for a time tracking tool. While access to Google Calendar makes sense for time tracking integration, the extension's permissions could theoretically be misused to access sensitive data across multiple domains. The activeTab permission, while common, allows the extension to interact with whatever page you're currently viewing when activated. The storage permission enables local data retention, which could include sensitive time tracking or calendar information.

Recommendations:

Given the medium risk level, consider running this extension in a separate Chrome profile if you handle highly sensitive information in your browser. Before installation, verify that TimeTackle Inc is indeed the legitimate company behind your time tracking service. Monitor the extension's behavior and revoke permissions if you notice any unexpected activity. Regularly review what data the extension has access to through Chrome's extension management settings. The risk is manageable for users who specifically need TimeTackle's time tracking functionality and trust the company.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://calendar.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.