CRX aminer
Extension icon

ColorPick Eyedropper

Version 1.3.7 View in Chrome Web Store

Last scanned: about 12 hours ago

Extension Details

Developer: pictureknow.com
Rating: 2.8 ★ (32 ratings)
Users: 20,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a concerning trust profile with only 20,000 users and a poor 2.8-star rating from just 32 reviews, indicating user dissatisfaction. The developer "pictureknow.com" lacks clear company information or established reputation. For a color picker tool, these metrics suggest potential quality or functionality issues.

Concerns:

The most alarming aspect is the proxy permission, which is completely unnecessary for a color picker tool and could be used to intercept or redirect web traffic maliciously. The broad host permissions (<all_urls>) are excessive - a legitimate eyedropper only needs access to the current tab, not all websites. The content scripts targeting specific Chinese e-commerce sites (Taobao, Tmall, JD.com) is suspicious and unrelated to color picking functionality. The combination of proxy control and universal website access creates significant potential for data theft, traffic manipulation, or privacy violations.

Recommendations:

Do not install this extension due to the proxy permission and suspicious targeting of e-commerce sites. If you need a color picker, choose alternatives like "ColorZilla" or "Eye Dropper" which have better ratings and appropriate permissions. If you must use this extension for testing purposes, run it in a completely isolated Chrome profile with no saved passwords or sensitive data, and monitor network traffic carefully.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: proxy
This extension has the proxy permission. Can control proxy settings. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.