CRX aminer
Extension icon

Serasa Experian - Certificado Digital

Version 1.0.14 View in Chrome Web Store

Last scanned: about 1 hour ago

Extension Details

Rating: 1.5 ★ (32 ratings)
Users: 50,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension is associated with Serasa Experian, a well-known Brazilian credit bureau and financial services company, which provides some legitimacy. However, the extremely low rating of 1.5 stars from 32 reviews is concerning and suggests significant user dissatisfaction. With 50,000 users, it has moderate adoption but the poor ratings indicate potential functionality or security issues.

Concerns:

The primary concern is the nativeMessaging permission, which allows the extension to communicate with native applications on the user's computer. This is a powerful capability that could potentially be exploited to access system resources or execute local programs. The content scripts run on specific domains including certificadodigital.com.br and sydle.one, plus a local IP address (10.96.189.153:8080), which suggests internal network access. The use of Manifest V2 presents additional security risks as it lacks the enhanced protections of V3. The poor user ratings combined with these technical permissions create a concerning profile.

Recommendations:

Given the medium risk level, consider running this extension in a separate Chrome profile to isolate its capabilities from your main browsing environment. Monitor the extension's behavior closely and be cautious about what native applications might be accessed. Consider whether the digital certificate functionality is essential enough to justify the security trade-offs, and look for alternative solutions with better user ratings and more restrictive permissions if possible.

Findings

MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.