CRX aminer
Extension icon

Mapify - AI Summarizer & Mind Map Generator for YouTube, PDFs, and Webpages

Version 1.6.3 View in Chrome Web Store

Last scanned: about 7 hours ago

Extension Details

Developer: XMIND LTD.
Rating: 4.4 ★ (22 ratings)
Users: 100,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension comes from XMIND LTD., a legitimate company known for mind mapping software, which adds some credibility. With 100,000 users and a 4.4-star rating from 22 reviews, it shows reasonable adoption and user satisfaction. The functionality described (AI summarization and mind mapping for various content types) aligns with XMIND's core business.

Concerns:

The extension's permissions are extremely broad and concerning for its stated purpose. The combination of cookies access, tabs permission, and universal host permissions creates a powerful surveillance capability. The ability to inject content scripts into all websites means it can read everything you do online, including sensitive information like passwords, banking details, and private communications. The cookies permission allows it to access authentication tokens and session data across all sites. These permissions far exceed what's necessary for summarizing content and creating mind maps.

Recommendations:

Given the critical risk level, consider running this extension in a completely separate Chrome profile dedicated only to content you're comfortable having monitored. Alternatively, look for similar tools that operate as standalone web applications rather than browser extensions. If you must use it, regularly review what data it might be collecting and consider using it only on non-sensitive websites. The broad permissions make this extension capable of comprehensive data harvesting regardless of the developer's intentions.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.