CRX aminer

Starting analysis...

Extension icon

HackBar

Version 1.2.8 View in Chrome Web Store

Last scanned: 12 days ago | force re-scan

Extension Details

Rating: 4.2 ★ (54 ratings)
Size: 1.72MiB
Last Updated: December 30, 2024
Users: 80,000

Context-Aware Verdict

HIGH
Risk Level
Trust Factors:
- The extension has a relatively high number of users (80,000), which could indicate some level of trust from the user community.
- However, the lack of developer information and a company reputation raises concerns about the extension's trustworthiness.
Concerns:
- The extension has broad host permissions (*://*/*), allowing it to access and potentially intercept data from any website, posing a significant privacy risk.
- The webRequest permission enables the extension to intercept and modify web requests, which could be exploited for malicious purposes, such as injecting malicious code or compromising user data.
- The Content Security Policy (CSP) allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution, increasing the risk of hidden malicious code or resource-intensive operations.
Recommendations:
- Exercise caution when installing and using this extension, as it poses significant security and privacy risks.
- Consider running the extension in a separate Chrome profile or a sandboxed environment to isolate it from your primary browsing activities.
- Regularly monitor the extension's behavior and check for any suspicious activities or performance issues.
- If possible, seek alternative extensions from reputable developers or companies with a proven track record of security and privacy practices.
- Keep your browser and extensions up-to-date to ensure you have the latest security patches and updates.

Security Analysis

HIGH
Overall Risk
Based on 4 total findings, ranked without considering overall context, including 3 high-risk and 1 medium-risk findings.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.