CRX aminer

Version 3.11.0 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension lacks critical identifying information including name, description, author details, user count, and ratings, making it impossible to assess developer credibility or community trust. The absence of basic metadata raises immediate red flags about the extension's legitimacy and transparency.

Concerns:

The extension requests powerful webRequest permissions that allow intercepting and modifying all web traffic, which is excessive for most legitimate use cases. While host permissions are limited to specific Brazilian government tax sites (NFe and CTe portals) and fsist.com.br, the combination of webRequest access with scripting permissions creates significant security risks. The extension can potentially capture sensitive financial and tax data, modify government portal interactions, or inject malicious code. The lack of developer information and extension details makes it impossible to verify the legitimacy of accessing these sensitive government systems.

Recommendations:

Do not install this extension due to insufficient transparency and high-risk permission combination. If you must use it for legitimate business purposes, run it in a completely isolated Chrome profile with no other extensions or saved passwords. Verify the extension's authenticity through official channels before installation. Consider alternative solutions that don't require such broad web request interception capabilities. Monitor network activity if installed to detect any unauthorized data transmission.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.