CRX aminer
Extension icon

Avast SafePrice | Comparison, deals, coupons

Version 23.1.1691 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Developer: https://www.avast.com/
Rating: 3.5 ★ (12 ratings)
Users: 20,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension is developed by Avast, a well-established cybersecurity company with a strong reputation in the antivirus and security software industry. However, the extension has concerning metrics with only 20,000 users and a modest 3.5-star rating from just 12 reviews, which is unusually low adoption for a major company's product. This could indicate either a newer release or user concerns about the extension's functionality.

Concerns:

The extension requests extremely broad permissions that far exceed what's necessary for price comparison functionality. The combination of webRequest, webNavigation, and tabs permissions allows comprehensive monitoring and modification of all web browsing activity. The universal content script injection (*://*/*) means the extension can access and modify every website visited, including sensitive sites like banking or email platforms. These permissions create significant privacy and security risks, as the extension could theoretically intercept login credentials, financial information, or personal data across all websites.

Recommendations:

Given the critical risk level, consider running this extension in a completely separate Chrome profile dedicated solely to shopping activities. Alternatively, look for price comparison extensions with more limited permissions that only activate on shopping sites. Before installation, carefully review Avast's privacy policy regarding data collection and sharing practices. Monitor your browsing behavior for any unusual activity if you choose to install it, and consider uninstalling if you notice performance issues or unexpected behavior.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.