CRX aminer
Extension icon

Web Capture - HTML to React with MagicPath

Version 1.0.0 View in Chrome Web Store

Last scanned: 12 days ago | force re-scan

Extension Details

Developer: magicpath.ai
Rating: 4.5 ★ (47 ratings)
Users: 9,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a reasonable user base of 9,000 downloads and a solid 4.5-star rating from 47 reviews, suggesting legitimate functionality. The developer domain "magicpath.ai" appears to be a legitimate AI-focused company, and the extension's purpose of converting HTML to React code is a valid developer tool use case.

Concerns:

The extension requests extremely broad permissions that far exceed what's necessary for HTML-to-React conversion. The <all_urls> host permissions and content script injection capabilities allow it to access and modify any website you visit, not just when actively using the tool. The clipboardWrite permission, while potentially useful for copying generated code, could be misused to inject malicious content. The combination of these permissions creates a powerful surveillance and data collection capability that could capture sensitive information from banking sites, email, or other private web applications.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to development work only. Disable the extension when not actively converting HTML to React code. Before installing, verify if the functionality truly requires such broad permissions - many similar tools work with more limited scope. Monitor your clipboard content after using the extension. If you proceed with installation, avoid using it while accessing sensitive websites like banking or email platforms.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: clipboardWrite
This extension has the clipboardWrite permission. Can modify clipboard content. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.