CRX aminer
Extension icon

Test Retail OfficeSuite UC® for Chrome™

Version 50.0.4.0 View in Chrome Web Store

Last scanned: about 6 hours ago

Extension Details

Rating: 4.0 ★ (12 ratings)
Users: 636

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has very limited trust indicators with only 636 users and 12 ratings, suggesting minimal adoption. The lack of clear developer information and company details raises transparency concerns. The "Test Retail" prefix in the name suggests this may be a development or testing version rather than a production-ready extension, which is concerning for end users.

Concerns:

The extension requests extremely broad permissions that appear excessive for a typical office suite tool. The identity and identity.email permissions combined with broad host access to all websites creates significant privacy risks. The ability to inject content scripts into all URLs means this extension can read and modify any webpage you visit, including sensitive sites like banking or email. The notifications permission, while seemingly benign, could be used for social engineering attacks. The use of outdated Manifest V2 indicates the extension hasn't been updated to meet modern security standards.

Recommendations:

Given the high risk level, avoid installing this extension unless absolutely necessary for business operations. If required, run it in a completely separate Chrome profile isolated from personal browsing and sensitive accounts. Verify with your IT department that this is the legitimate version of OfficeSuite UC and not a malicious imposter. Consider requesting your organization use the official OfficeSuite extension instead. Monitor for any suspicious network activity or unexpected notifications if you must use this extension.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.