CRX aminer
Extension icon

ESUIT | Un Seen for Facebook™

Version 1.13.0 View in Chrome Web Store

Last scanned: 3 days ago | force re-scan

Extension Details

Developer: esuit.dev
Rating: 4.4 ★ (219 ratings)
Users: 20,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a solid user base of 20,000 users with a good rating of 4.4/5 stars from 219 reviews, indicating general user satisfaction. The developer uses the domain esuit.dev, which suggests some level of professionalism. The extension's purpose - providing "unseen" functionality for Facebook - is clearly defined and matches its requested permissions.

Concerns:

The primary concern is the broad host permissions that grant access to Facebook's main domains and Messenger. While these permissions align with the extension's stated purpose, they provide significant access to sensitive social media data including private messages, posts, and personal information. The storage permission allows the extension to retain data locally, which could include sensitive Facebook content. The scripting permission enables code injection into Facebook pages, creating potential for data harvesting beyond the intended "unseen" functionality.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to Facebook use to limit exposure of other browsing activities. Regularly review what data the extension might be storing locally. Monitor Facebook's activity logs for any unusual behavior. Since the extension modifies Facebook's read receipt functionality, be aware this could impact your social interactions. Only install if you specifically need the "unseen" feature and trust the developer with access to your Facebook data.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://www.facebook.com/*, https://web.facebook.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.