CRX aminer
Extension icon

Personalization Context

Version 0.0.58 View in Chrome Web Store

Last scanned: about 23 hours ago

Extension Details

Rating: 5.0 ★ (2 ratings)
Users: 332

Context-Aware Verdict

HIGH
Risk Level
Trust Factors:

The extension appears to be developed by or for Expedia Group, given its focus on travel-related domains (Expedia, Hotels.com, VRBO, etc.). However, several concerning factors undermine trust: extremely low user adoption (332 users), minimal rating data (only 2 reviews), missing developer information, and no clear description of functionality. The version number (0.0.58) suggests this may be in early development or testing phases.

Concerns:

The extension requests powerful permissions that create significant privacy and security risks. The cookies permission allows access to sensitive authentication data across all specified domains. The tabs permission enables monitoring and manipulation of browsing activity. The storage permission, while less critical, allows persistent data collection. Most concerning is the extensive list of host permissions covering dozens of travel-related domains plus internal testing environments, creating a broad attack surface. The lack of transparency about the extension's actual purpose makes it impossible to verify if these permissions are necessary.

Recommendations:

Given the high risk level, avoid installing this extension unless you have a specific business need and can verify its legitimacy through official Expedia channels. If installation is necessary, use a separate Chrome profile to isolate potential risks. Monitor your accounts on affected domains for unusual activity. Consider that this may be an internal tool not intended for public distribution, which would explain the limited user base and missing documentation.

Security Analysis

HIGH
Overall Risk
Based on 4 total findings, ranked without considering overall context, including 3 high-risk and 1 medium-risk findings.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.