CRX aminer
Extension icon

StayFree - Website Blocker, Web Usage Stats, Shorts Blocker

Version 2.5.8 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Developer: Sensor Tower
Rating: 4.7 ★ (2.5K ratings)
Users: 200,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension comes from Sensor Tower, a legitimate analytics company, which adds credibility. With 200,000 users and a strong 4.7-star rating from 2.5K reviews, it appears to have genuine user adoption and satisfaction. The extension's stated purpose as a website blocker and usage tracker aligns with productivity tools that typically require extensive permissions.

Concerns:

The extension's permission set is extremely broad for its stated functionality. While website blocking legitimately requires webNavigation and tabs permissions, the universal host permissions (*://*/*) and content script injection across all websites creates significant attack surface. The scripting permission combined with broad access means this extension can read, modify, or steal data from any website you visit. The search permission seems unnecessary for a website blocker. Most concerning is that these permissions would allow complete monitoring of browsing activity and potential credential theft, far exceeding what's needed for basic website blocking functionality.

Recommendations:

Despite the developer's reputation, the permission scope presents substantial privacy and security risks. Consider running this extension in a separate Chrome profile dedicated to productivity tools, isolating it from sensitive browsing activities like banking or work accounts. Alternatively, look for website blockers with more limited permissions that don't require universal site access. If you must use this extension in your main profile, regularly audit what data it might be collecting and consider the trade-off between productivity features and privacy exposure.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.