CRX aminer
Extension icon

SocialPostBuddy

Version 1.1.1.11 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Developer: socialpostbuddy.com
Users: 13

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has extremely low adoption with only 13 users, which is concerning for legitimacy. The lack of rating information and missing last updated date suggests poor maintenance or potential abandonment. The developer is identified only by a domain name (socialpostbuddy.com) without additional verification details, which provides limited accountability. The extension's purpose is unclear from the minimal description provided.

Concerns:
- The tabs permission is particularly concerning given the vague nature of this extension, as it allows comprehensive access to browse all open tabs, URLs, and potentially sensitive information
- Very low user base (13 users) combined with missing critical metadata raises red flags about the extension's legitimacy
- Manifest V2 usage indicates outdated security practices and potential vulnerabilities
- The storage permission, while common, could be used to persist malicious data or track user behavior
- Lack of transparency about the extension's actual functionality makes it impossible to determine if permissions are justified
Recommendations:

Given the high-risk tabs permission combined with extremely low adoption and poor transparency, avoid installing this extension entirely. If you must test it for research purposes, use a completely separate Chrome profile with no sensitive data or important accounts logged in. Consider looking for well-established alternatives with clear functionality descriptions, higher user bases, and recent updates to Manifest V3.

Findings

HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.