CRX aminer

Starting analysis...

Extension icon

Skrapp.io - Email Finder

Version 1.2.7 View in Chrome Web Store

Last scanned: about 2 months ago | force re-scan

Extension Details

Developer: skrapp.io
Rating: 4.7 ★ (422 ratings)
Size: 616KiB
Last Updated: February 27, 2025
Users: 100,000
Developer Info: Skrapp Private Limited

Context-Aware Verdict

HIGH
Risk Level
Trust Factors:
- The extension has over 100,000 users and a relatively high rating of 4.7, indicating some level of trust from users.
- However, the developer "Skrapp Private Limited" does not appear to be a well-known or reputable company, which raises some concerns.
Concerns:
- The extension requests broad host permissions to access all websites, which is unnecessary for an email finder extension and raises privacy concerns.
- It has high-risk permissions like webRequest and tabs, which could potentially be abused to intercept web traffic or manipulate browser tabs.
- The extension also requests access to sensitive domains like LinkedIn, which could expose user data on those sites.
Recommendations:
- Exercise caution when installing this extension, as it has several high-risk permissions and broad access that could potentially compromise your security and privacy.
- Consider using the extension in a separate browser profile or a sandboxed environment to isolate it from your main browsing activity.
- Regularly review the extension's permissions and activity, and uninstall it if you notice any suspicious behavior.
- Look for alternative email finder extensions from more reputable developers that request only the necessary permissions for their stated functionality.

Security Analysis

HIGH
Overall Risk
Based on 5 total findings, ranked without considering overall context, including 3 high-risk and 2 medium-risk findings.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: *://www.linkedin.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.