CRX aminer
Extension icon

Grayscale

Version 2.0.4.0 View in Chrome Web Store

Last scanned: about 12 hours ago

Extension Details

Rating: 4.0 ★ (4 ratings)
Users: 7,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a relatively small user base of 7,000 users with only 4 ratings, which provides limited community validation. The 4.0 rating is decent but based on very few reviews. The lack of clear author information and developer details raises transparency concerns. The extension appears to be related to a service at gograyscale.com, suggesting it may be a legitimate productivity tool for website grayscale filtering.

Concerns:

The most significant concern is the combination of broad host permissions covering all URLs and content script injection capabilities across all websites. This creates a powerful attack surface that could be exploited to steal credentials, personal data, or track browsing behavior across the entire web. The storage permission, while necessary for functionality, combined with these broad permissions could enable persistent data collection. The contextMenus permission is relatively benign but adds to the overall permission footprint.

Recommendations:

Given the high-risk profile, consider running this extension in a separate Chrome profile dedicated to non-sensitive browsing activities. Before installation, verify the legitimacy of the gograyscale.com service and ensure it aligns with your needs. Monitor the extension's behavior after installation and consider alternatives with more limited permissions if available. Only install if the grayscale functionality is essential to your workflow, and regularly review whether you still need it installed.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.