CRX aminer
Extension icon

Smart Sidebar: Chat GPT, Claude & DeepSeek

Version 2.0.5 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Rating: 4.6 ★ (2.7K ratings)
Users: 400,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a solid user base of 400,000 users and a strong 4.6-star rating from 2,700+ reviews, indicating general user satisfaction. The name suggests it provides AI chat functionality through a sidebar interface, which aligns with legitimate productivity tools. However, the lack of visible developer information reduces transparency and accountability.
Concerns: The extension's permissions are extremely broad and concerning for its stated purpose. The <all_urls> host permissions and content script injection capabilities allow it to access and modify any website you visit, which is excessive for a sidebar chat tool. This creates significant privacy and security risks, as the extension could potentially capture sensitive information like passwords, financial data, or personal communications from any website. The storage permission, while necessary for functionality, combined with the broad access creates additional data collection concerns.
Recommendations: Given the high risk level, consider running this extension in a separate Chrome profile dedicated to non-sensitive browsing activities. Avoid using it while accessing banking, email, or other sensitive websites. Monitor your browsing behavior and be cautious about what information might be accessible to the extension. Consider alternative AI chat tools that don't require such extensive permissions, such as visiting AI websites directly or using extensions with more limited scope. Regularly review what data the extension might be collecting and storing.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.