CRX aminer

Starting analysis...

Extension icon

Markdown Here

Version 2.16.0 View in Chrome Web Store

Last scanned: 3 days ago | force re-scan

Extension Details

Rating: 4.5 ★ (371 ratings)
Users: 100,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

Markdown Here is a well-established extension with 100,000 users and a solid 4.5-star rating from 371 reviews. The extension serves a legitimate purpose of converting Markdown text to formatted HTML in web applications like Gmail, which explains its popularity among developers and technical users. The moderate user base and positive ratings suggest it has been reliable for its intended functionality.

Concerns:

The extension requests several permissions that, while reasonable for its stated purpose, create potential attack vectors. The activeTab permission allows access to webpage content when activated, which could be misused to read sensitive information from any tab. The scripting permission enables code injection into web pages, creating opportunities for malicious behavior if the extension were compromised. The contextMenus permission, while useful for user experience, adds another entry point for potential exploitation. The storage permission allows data persistence, which could be used to collect and store user information.

Recommendations:

Given the medium risk level, consider running this extension in a separate Chrome profile if you frequently work with sensitive documents or confidential information. Monitor the extension's behavior and disable it when not actively needed for Markdown conversion. Regularly review your installed extensions and ensure this one continues to receive updates from its developer. The risk is manageable for most users, but extra caution is warranted in high-security environments.

Findings

MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.