CRX aminer
Extension icon

Chinese words separator: Chinese dictionary

Version 8.24.84.3240 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Rating: 4.8 ★ (49 ratings)
Users: 4,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a relatively small user base of 4,000 users and a high rating of 4.8 from 49 reviews, which suggests positive user experience among those who have tried it. However, the limited adoption and lack of clear developer information raises questions about transparency and accountability. The extension appears to be a Chinese language learning tool based on its name and description.

Concerns:

The extension exhibits several red flags that justify the critical risk rating. The combination of identity permission with broad host permissions creates a dangerous scenario where the extension could potentially access user authentication data across all websites. The content script injection capability on all URLs means it can read and modify any webpage content, including sensitive information like passwords, financial data, and personal communications. The tabs permission allows monitoring of browsing behavior, while access to Google accounts specifically raises concerns about potential data harvesting from user profiles.

Recommendations:

Given the critical risk level, avoid installing this extension unless absolutely necessary. If you must use it, create a dedicated Chrome profile isolated from your main browsing activities, especially those involving sensitive accounts or financial services. Consider alternative Chinese language tools that require fewer permissions. Regularly monitor your Google account activity for any suspicious access patterns if you choose to proceed with installation.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://accounts.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.