CRX aminer
Extension icon

Slate for Rise

Version 2.1.1 View in Chrome Web Store

Last scanned: about 1 hour ago

Extension Details

Rating: 4.7 ★
Users: 120

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a very small user base of only 120 users, which raises concerns about its legitimacy and testing. While it maintains a 4.7-star rating, the limited adoption suggests minimal community vetting. The lack of visible developer information and company details makes it difficult to assess the publisher's reputation and accountability.

Concerns:

The extension requests excessive permissions that seem disproportionate for a tool designed to work with Rise (Articulate's e-learning platform). The downloads permission combined with broad host access creates potential for data exfiltration. The webNavigation permission allows comprehensive tracking of browsing behavior beyond the intended Rise platform. The unsafe WebAssembly execution policy is particularly concerning as it could hide malicious code. The broad host permissions extend far beyond Rise-related domains, including access to GitHub, HuggingFace, and various CDNs, which appears unnecessary for the stated purpose.

Recommendations:

Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile with limited sensitive data and bookmarks. Consider whether the functionality is truly necessary, as legitimate Rise integrations typically don't require such extensive permissions. Monitor your download folder and browser activity closely if you proceed with installation. Contact Articulate directly to verify if this is an official or recommended tool for their platform.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: *://articulate-us.s3.amazonaws.com/*, *://fonts.googleapis.com/*, https://raw.githubusercontent.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.