CRX aminer

Starting analysis...

Extension icon

Auto Refresh Plus

Version 3.0.0 View in Chrome Web Store

Last scanned: 22 days ago | force re-scan

Extension Details

Rating: 4.8 ★ (1.5K ratings)
Users: 100,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors: The extension has a strong user base with 100,000 users and an excellent rating of 4.8 stars from 1,500 reviews, indicating generally positive user experiences. The functionality described (auto refresh) is straightforward and commonly needed by users.
Concerns: The primary concern is the overly broad host permissions (<all_urls>) which grants the extension access to all websites you visit. For an auto refresh tool, this level of access seems excessive and creates potential privacy risks. The extension could theoretically monitor your browsing activity across all sites, collect sensitive data from web pages, or inject unwanted content. The storage permission, while necessary for saving refresh settings, adds another layer of data collection capability.

The combination of broad website access and local storage permissions creates a scenario where the extension could potentially track and store your browsing patterns, though this may not be the intended functionality.

Recommendations: Consider running this extension in a separate Chrome profile dedicated to non-sensitive browsing activities. Before installing, verify that the auto refresh functionality truly requires access to all websites rather than just the specific pages you want to refresh. Look for alternative auto refresh extensions that request more limited permissions. If you proceed with installation, regularly review what data the extension might be storing and monitor your browsing experience for any unexpected behavior.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.