CRX aminer
Extension icon

Slate for Rise

Version 2.1.1 View in Chrome Web Store

Last scanned: 1 day ago | force re-scan

Extension Details

Rating: 0.0 ★
Users: 82

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has extremely low adoption with only 82 users and no ratings, which provides no community validation. The lack of author information and developer details raises significant transparency concerns. The extension appears to be designed for Articulate Rise, a legitimate e-learning platform, but the minimal user base suggests it may be unofficial or experimental.

Concerns:

The extension requests excessive permissions that seem disproportionate for a simple Rise integration tool. The downloads permission combined with broad host access creates potential for data exfiltration. The webNavigation permission allows comprehensive browsing tracking beyond the stated purpose. The unsafe WebAssembly execution policy ('wasm-unsafe-eval') is particularly concerning as it can hide malicious code execution. The broad host permissions spanning multiple domains including AWS S3, GitHub, and HuggingFace repositories suggest functionality far beyond basic Rise integration.

Recommendations:

Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile with no sensitive data or accounts. Consider using official Articulate tools instead. If installation is necessary, monitor network activity and file downloads closely. The combination of low user adoption, missing developer information, and excessive permissions suggests this extension may be malicious or poorly designed. Wait for official alternatives or extensions with better security practices and community validation.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: *://articulate-us.s3.amazonaws.com/*, *://fonts.googleapis.com/*, https://raw.githubusercontent.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.