CRX aminer
Extension icon

Skrapp.io - Email Finder

Version 2.5.2 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Developer: Skrapp Private Limited
Rating: 4.8 ★ (551 ratings)
Users: 200,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a solid user base of 200,000 users and maintains a high rating of 4.8 stars from 551 reviews, indicating general user satisfaction. The developer, Skrapp Private Limited, appears to be a legitimate company focused on email finding services. The extension's purpose aligns with its requested permissions for LinkedIn data extraction.
Concerns: The extension requests several powerful permissions that create significant security risks. The webRequest permission allows interception and modification of all web traffic, which could be exploited for data theft or malicious redirects. The tabs permission provides access to all browser tab information, potentially exposing sensitive browsing activity. The broad host permissions combined with LinkedIn access creates opportunities for unauthorized data collection beyond the stated purpose. The storage permission, while necessary for functionality, could be used to persist stolen data locally.
Recommendations: Given the high-risk permission set, consider running this extension in a separate Chrome profile dedicated to professional networking activities. Only use it when actively prospecting on LinkedIn, and disable it when not needed. Regularly review the extension's activity through Chrome's extension management page. Monitor your LinkedIn account for any unusual activity. Consider whether the email finding functionality justifies the extensive permissions required, and evaluate alternative tools with more limited access requirements if privacy is a primary concern.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: *://www.linkedin.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.