CRX aminer
Extension icon

RevSeller

Version 3.1.19 View in Chrome Web Store

Last scanned: about 9 hours ago

Extension Details

Developer: https://revseller.com/
Rating: 4.8 ★ (102 ratings)
Users: 50,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

RevSeller appears to be a legitimate Amazon seller tool with a strong user base of 50,000 users and an excellent 4.8-star rating from 102 reviews. The extension is developed by revseller.com, suggesting it's backed by an established company in the Amazon seller space. The high rating and substantial user base indicate positive user experiences and functionality that delivers value to Amazon sellers.

Concerns:

The primary concern is the identity permission, which allows access to your Google account information - this is rarely necessary for Amazon seller tools and represents a significant privacy risk. The broad host permissions extending across all Amazon domains and images could potentially be exploited to capture sensitive seller data, financial information, or customer details. The extension's access to Amazon Seller Central, where sensitive business and financial data resides, amplifies these risks. While the permissions align with an Amazon seller tool's functionality, the identity permission seems excessive for the stated purpose.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to Amazon selling activities to isolate potential risks from your main browsing. Before installation, verify the extension's necessity for the identity permission by checking their privacy policy and terms of service. Monitor your Google account activity for any unusual access patterns. Given the extension's strong reputation and user base, the risk may be acceptable for serious Amazon sellers, but casual users should exercise caution.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: *://www.amazon.com/*, *://www.amazon.ca/*, *://*.images-amazon.com/*, https://sellercentral.amazon.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.