CRX aminer
Extension icon

Shadowban Scanner for Twitter / X

Version 4.1.0 View in Chrome Web Store

Last scanned: about 1 hour ago

Extension Details

Developer: shadowban-scanner.roboin.io
Rating: 3.8 ★ (32 ratings)
Users: 40,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a moderate user base of 40,000 users and a decent rating of 3.8/5, suggesting general user satisfaction. The specific purpose of detecting Twitter/X shadowbans is legitimate and addresses a real user concern. The developer domain appears dedicated to this functionality, which adds some credibility. However, the relatively low number of reviews (32) compared to the user base may indicate limited user engagement or feedback.

Concerns:

The primary concern is the broad host permissions for Twitter/X domains, which grants extensive access to all content on these platforms. While the storage permission is standard for functionality, the extension can potentially access all user interactions, tweets, direct messages, and personal data on Twitter/X. The high-risk finding regarding broad host permissions is particularly concerning given the sensitive nature of social media data. The extension could theoretically monitor all Twitter/X activity, not just shadowban detection.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to Twitter/X usage to limit potential data exposure from other browsing activities. Regularly review the extension's behavior and disable it when not actively checking for shadowbans. Monitor for any unusual network activity or data requests. Given the moderate risk level, users should weigh the utility of shadowban detection against the broad access permissions required.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://*.twitter.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.