CRX aminer

Starting analysis...

Extension icon

Hue: More Colors for Google Calendar

Version 1.0.5 View in Chrome Web Store

Last scanned: about 1 month ago | force re-scan

Extension Details

Rating: 3.6 ★ (40 ratings)
Users: 10,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a moderate user base of 10,000 users and a rating of 3.6/5 from 40 reviews, which suggests mixed user satisfaction. The specific focus on Google Calendar color enhancement appears legitimate for its stated purpose. However, the lack of detailed developer information and company reputation data limits trust assessment.

Concerns:

The primary concern is the broad host permissions that allow access to both HTTP and HTTPS versions of Google Calendar. While this access is necessary for the extension's functionality, it creates potential exposure to sensitive calendar data including personal appointments, meeting details, and scheduling information. The storage permission, while standard for customization features, could be used to retain user data locally. The medium overall risk rating with one high-risk finding indicates some security considerations that warrant attention.

Recommendations:

Given the medium risk level, consider running this extension in a separate Chrome profile dedicated to Google Calendar use if you handle highly sensitive scheduling information. Before installation, review the extension's privacy policy if available and monitor what data it accesses. Regularly check for updates to ensure you have the latest security patches. If you notice any unusual behavior or unauthorized data access, remove the extension immediately. The legitimate functionality appears to justify the permissions requested, but maintain awareness of the sensitive data exposure.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://calendar.google.com/*, http://calendar.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.