CRX aminer
Extension icon

InboxXray — Scam and Phishing Email Checker

Version 1.3.0 View in Chrome Web Store

Last scanned: about 12 hours ago

Extension Details

Developer: inboxxray.app
Rating: 5.0 ★
Users: 2

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has extremely limited adoption with only 2 users despite claiming to provide email security services. While it has a perfect 5.0 rating, this is meaningless with such a tiny user base. The developer domain (inboxxray.app) appears to be purpose-built for this extension, providing no established reputation or track record. The lack of transparency around company information and the recent nature of the extension raises significant trust concerns.

Concerns:

The identity permission is particularly concerning for an email checker, as it grants access to your Google/Microsoft account identity information beyond what's necessary for scanning emails. The broad host permissions spanning multiple major email providers (Gmail, Outlook variants) combined with access to Microsoft Graph API and authentication endpoints creates an extensive attack surface. The extension can inject content scripts into your email interfaces and communicate with external APIs, potentially exposing sensitive email content and authentication tokens. The storage permission allows persistent data collection on your device.

Recommendations:

Given the high risk profile and minimal user adoption, avoid installing this extension entirely. If email security scanning is needed, choose established alternatives with proven track records and larger user bases. The combination of identity access, broad email provider permissions, and unknown developer reputation makes this extension unsuitable for handling sensitive email communications. Consider using built-in email security features or well-established security solutions instead.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://mail.google.com/*, https://outlook.office.com/*, https://outlook.live.com/*, https://outlook.office365.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.