CRX aminer
Extension icon

Jira Product Discovery

Version 1.1.6 View in Chrome Web Store

Last scanned: 2 days ago | force re-scan

Extension Details

Rating: 3.9 ★ (18 ratings)
Users: 10,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension appears to be legitimate Atlassian software for Jira Product Discovery with 10,000 users and a 3.9-star rating. However, the lack of clear developer information and company verification raises some concerns about authenticity verification.

Concerns:

The extension requests extremely broad permissions that seem excessive for a typical Jira integration tool. The <all_urls> host permission allows access to every website you visit, not just Atlassian domains. The webRequest permission enables intercepting and modifying all web traffic, while cookies permission allows reading/writing sensitive authentication data across all sites. The combination of these permissions creates significant privacy and security risks, as the extension could theoretically monitor all browsing activity, steal login credentials, or modify web content on any website.

The unlimitedStorage permission, while less critical, allows indefinite data collection without storage limits.

Recommendations:

Install this extension only if you absolutely need Jira Product Discovery functionality and trust Atlassian completely. Consider running it in a separate Chrome profile dedicated to work activities to isolate potential risks from personal browsing. Regularly review what data the extension might be collecting and consider uninstalling when not actively needed. Verify the extension's authenticity through official Atlassian channels before installation, as the broad permissions make this a high-value target for malicious impersonation.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.