CRX aminer
Extension icon

BibTeX Connect – Powered by CiteDrive

Version 5.1.0 View in Chrome Web Store

Last scanned: about 10 hours ago

Extension Details

Developer: citedrive.com
Rating: 4.0 ★ (6 ratings)
Users: 4,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a moderate user base of 4,000 users and maintains a decent 4.0-star rating, though based on only 6 reviews which limits reliability. The developer citedrive.com appears to be associated with academic citation management, which aligns with the extension's stated purpose. However, the low review count and relatively small user base provide limited validation of trustworthiness.
Concerns: The extension's permissions are extremely broad and concerning for its stated academic purpose. The combination of universal host permissions (https://*/*) and content script injection across all URLs creates significant security risks. For a BibTeX/citation management tool, accessing every website on the internet seems unnecessary and excessive. The ability to inject scripts into all websites could enable data theft, credential harvesting, or unauthorized website modifications. The storage permission, while reasonable for citation management, becomes more concerning when combined with the broad access capabilities.
Recommendations: Given the high-risk profile, consider running this extension in a separate Chrome profile dedicated to academic work only. Before installation, verify the legitimacy of citedrive.com and their privacy practices. Monitor the extension's behavior closely and consider alternative citation management tools with more restrictive permissions. If you must use this extension, disable it when not actively conducting research and avoid using it while accessing sensitive websites like banking or personal accounts.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.