CRX aminer
Extension icon

ChartScoutAssist

Version 1.753 View in Chrome Web Store

Last scanned: about 14 hours ago

Extension Details

Users: 1,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a relatively small user base of 1,000 users, which limits community validation. The lack of visible rating, author information, and developer details raises transparency concerns. However, the specific targeting of healthcare platforms (Athenanet and EmergeCDS) suggests a specialized medical workflow tool, which could indicate legitimate business use.

Concerns:

The tabs permission is overly broad for an extension that appears to focus on specific healthcare platforms. This permission allows access to all browser tabs and their URLs, not just the medical sites it targets. The extension's scope is limited to healthcare platforms through content scripts, but the tabs permission extends beyond this boundary. The use of Manifest V2 indicates outdated security standards, as newer extensions should migrate to the more secure V3. The absence of developer information and ratings makes it difficult to verify legitimacy.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to healthcare work to isolate potential risks from personal browsing. Verify the extension's legitimacy with your healthcare organization's IT department before installation. Monitor for any unusual browser behavior or unauthorized tab access. If possible, seek alternatives that use Manifest V3 and have more transparent developer information. Given the healthcare context, ensure compliance with HIPAA and other medical data protection requirements.

Findings

HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.