CRX aminer
Extension icon

Carrot

Version 0.6.8 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Rating: 4.2 ★ (77 ratings)
Users: 50,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a moderate user base of 50,000 users and a decent rating of 4.2/5 from 77 reviews, suggesting reasonable user satisfaction. However, the lack of developer information and missing description raises transparency concerns. The extension appears to be specifically designed for Codeforces, a competitive programming platform, which is a legitimate use case.

Concerns:

The primary concern is the broad host permissions for all Codeforces domains (*://*.codeforces.com/*), which could potentially access sensitive user data across the entire platform including login credentials, contest submissions, and personal information. The unlimited storage permission combined with regular storage access allows the extension to collect and store substantial amounts of user data indefinitely. The missing extension description makes it difficult to verify if these permissions are justified for the stated functionality.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to competitive programming activities to isolate potential risks from your main browsing profile. Before installation, research the extension's actual functionality through user reviews or community forums to ensure the permissions align with its purpose. Monitor the extension's behavior and consider alternatives with more transparent developer information and clearer permission justifications. Given the specific domain targeting, the risk is somewhat contained to Codeforces usage rather than general web browsing.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.