CRX aminer
Extension icon

Sort By Review Count for Amazon

Version 5.24.0314 View in Chrome Web Store

Last scanned: about 6 hours ago

Extension Details

Rating: 1.8 ★ (133 ratings)
Users: 4,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a concerning trust profile with only 4,000 users and an extremely poor rating of 1.8 out of 5 stars from 133 reviews, indicating significant user dissatisfaction. The lack of visible developer information raises additional transparency concerns. While the functionality appears legitimate for Amazon shopping enhancement, the poor user feedback suggests potential issues with reliability or behavior.

Concerns:

The extension requests access to all major Amazon domains globally, which is appropriate for its stated purpose but creates a broad attack surface. The inclusion of extensionpay.com in content scripts suggests monetization features that may not be clearly disclosed to users. The activeTab and storage permissions, while reasonable for the functionality, could be misused given the poor reputation. The low rating combined with broad Amazon access permissions creates potential for data harvesting from shopping activities, including browsing patterns, purchase history, and personal information visible on Amazon pages.

Recommendations:

Given the high risk profile, avoid installing this extension. The extremely poor user rating of 1.8 stars is a major red flag that suggests serious functionality or trustworthiness issues. If you absolutely need Amazon sorting functionality, research well-reviewed alternatives with better ratings and more transparent developers. If you must use this extension, run it in a completely separate Chrome profile and avoid accessing sensitive account information while it's active.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: *://*.amazon.ae/*, *://*.amazon.at/*, *://*.amazon.ca/*, *://*.amazon.cn/*, *://*.amazon.co.jp/*, *://*.amazon.co.uk/*, *://*.amazon.com.au/*, *://*.amazon.com.br/*, *://*.amazon.com.mx/*, *://*.amazon.com.sg/*, *://*.amazon.com.tr/*, *://*.amazon.com/*, *://*.amazon.de/*, *://*.amazon.es/*, *://*.amazon.fr/*, *://*.amazon.ie/*, *://*.amazon.in/*, *://*.amazon.it/*, *://*.amazon.nl/*, *://*.amazon.eg/*, *://*.amazon.sa/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.