CRX aminer
Extension icon

LTK Product Link

Version 0.18.3 View in Chrome Web Store

Last scanned: about 9 hours ago

Extension Details

Developer: https://creator.shopltk.com/
Rating: 2.2 ★ (31 ratings)
Users: 30,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a concerning trust profile with only 30,000 users and a poor 2.2-star rating from 31 reviews, suggesting user dissatisfaction. The developer appears to be associated with LTK (formerly rewardStyle), a legitimate influencer marketing platform, which provides some credibility. However, the low rating indicates potential functionality or privacy issues that users have experienced.

Concerns:

The extension requests extremely broad permissions that seem excessive for a product linking tool. The combination of tabs permission with universal host permissions (http://*/*, https://*/*) creates significant privacy risks, allowing the extension to monitor and potentially manipulate all browsing activity across every website. The declarativeNetRequest permission could be used to modify network requests, while scripting permission enables code injection on any site. These capabilities far exceed what would be necessary for simply creating product links, raising questions about data collection practices and potential overreach.

Recommendations:

Given the high-risk permission set and poor user ratings, consider running this extension in a separate Chrome profile to isolate it from sensitive browsing activities. Before installation, carefully review LTK's privacy policy to understand data collection practices. Monitor the extension's behavior closely and consider alternatives with more limited permissions. If you must use it, disable it when not actively creating product links and regularly review what data it may have accessed through Chrome's extension management settings.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.