CRX aminer
Extension icon

Web Capture - HTML to React with MagicPath

Version 1.0.0 View in Chrome Web Store

Last scanned: 12 days ago | force re-scan

Extension Details

Developer: magicpath.ai
Rating: 4.2 ★ (25 ratings)
Users: 1,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a moderate user base of 1,000 users with a decent 4.2-star rating from 25 reviews, suggesting some level of user satisfaction. The developer is associated with magicpath.ai, which appears to be a legitimate AI-focused company. However, this is version 1.0.0, indicating it's a new release that may not have been thoroughly tested in the wild.
Concerns: The extension's permissions are extremely broad and concerning for its stated purpose of HTML to React conversion. The combination of all_urls host permissions and content script injection across all websites creates significant attack surface. The clipboardWrite permission could be misused to inject malicious content. Most concerning is that these extensive permissions seem unnecessary - a legitimate HTML-to-React tool should only need access to specific pages when actively being used, not blanket access to all websites.

The security findings reveal a pattern of overprivileged access that far exceeds what would be expected for a development tool. The broad content script injection capability means this extension can read sensitive data from banking sites, email, and other private web applications.

Recommendations: Run this extension in a completely separate Chrome profile isolated from your main browsing activities. Only enable it when specifically needed for development work. Consider alternative tools that require fewer permissions. Monitor your clipboard content after use and regularly review what data this extension might be accessing across your browsing sessions.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: clipboardWrite
This extension has the clipboardWrite permission. Can modify clipboard content. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.