CRX aminer
Extension icon

Birdie

Version 0.7.33 View in Chrome Web Store

Last scanned: about 11 hours ago

Extension Details

Developer: birdie.so
Rating: 5.0 ★ (6 ratings)
Users: 3,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has very limited trust indicators with only 3,000 users and just 6 reviews, despite a perfect 5.0 rating. The developer "birdie.so" lacks established reputation or transparency about their identity and business practices. The missing description is particularly concerning as users cannot understand what the extension actually does or why it needs such extensive permissions.

Concerns:

The extension requests an extremely broad set of permissions that would be excessive for most legitimate use cases. The combination of tabCapture, desktopCapture, and webRequest permissions suggests screen recording and network monitoring capabilities. The broad host permissions covering all websites (<all_urls>) combined with scripting permissions creates potential for data harvesting across the entire web. The unsafe WebAssembly execution policy could hide malicious code, while the downloads permission adds file system access risks. Most concerning is the lack of any description to justify these powerful permissions.

Recommendations:

Do not install this extension given the critical risk level and lack of transparency. If you must use it, run it in a completely isolated Chrome profile with no access to personal accounts or sensitive data. Consider alternative extensions with clearer purposes and more limited permissions. The combination of extensive permissions, minimal user base, and missing description strongly suggests this extension poses significant security and privacy risks that outweigh any potential benefits.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.