CRX aminer
Extension icon

Publishing.ai

Version 3.3.3 View in Chrome Web Store

Last scanned: 3 months ago | force re-scan

Extension Details

Rating: 5.0 ★ (3 ratings)
Users: 5,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has very limited trust indicators. With only 5,000 users and just 3 ratings (despite a perfect 5.0 score), the user base is quite small for meaningful validation. The lack of developer information, company details, and missing description raises significant transparency concerns. The extension name suggests AI-powered publishing functionality, but without a proper description, users cannot verify if the requested permissions align with stated purposes.

Concerns:

The combination of cookies permission with broad host permissions (https://*/*) creates a particularly concerning risk profile. This setup allows the extension to access and modify cookies across all HTTPS websites, potentially enabling session hijacking, unauthorized account access, or comprehensive tracking across the entire web. The declarativeNetRequest permission adds another layer of concern as it can modify network requests. For a publishing-focused tool, these permissions appear excessive and unnecessary. The small user base combined with perfect ratings from only 3 reviews suggests potential rating manipulation.

Recommendations:

Given the high risk level, avoid installing this extension on your primary browser profile. If you must use it, create a separate Chrome profile specifically for this extension and limit sensitive browsing activities in that profile. Consider alternative publishing tools with better transparency and more appropriate permission requests. Monitor your accounts for unusual activity if you've already installed this extension, and consider changing passwords for important accounts.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.