CRX aminer
Extension icon

AeroLeads.com - Free B2B Phone Number & Email Finder

Version 6.4.17 View in Chrome Web Store

Last scanned: about 8 hours ago

Extension Details

Developer: http://aeroleads.com/
Rating: 4.5 ★ (227 ratings)
Users: 20,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a decent user base of 20,000 users and a solid 4.5-star rating from 227 reviews, suggesting legitimate functionality. AeroLeads appears to be an established B2B lead generation service with a clear business model. The extension uses Manifest V3, which provides better security controls than older versions.

Concerns:

The extension's permissions are extremely broad for a B2B contact finder. The ability to inject content scripts into all websites (<all_urls>) is particularly concerning, as this goes far beyond what's needed to extract contact information from LinkedIn and Google. The tabs permission allows monitoring of all browsing activity, not just target sites. The combination of broad host permissions with content script injection creates significant privacy risks, as the extension could theoretically capture sensitive data from banking sites, email providers, or any other websites you visit.

The access to Google domains and LinkedIn makes sense for the stated functionality, but the universal content script injection does not.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated only to lead generation activities. Avoid using this profile for sensitive activities like banking or personal email. Monitor the extension's behavior and consider alternatives with more limited permissions. If you must use it in your main profile, regularly review what data the extension has access to and consider disabling it when not actively prospecting for leads.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://linkedin.com/*, https://*.linkedin.com/*, https://*.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.