CRX aminer
Extension icon

WaybackMachine

Version 1.1 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Rating: 3.4 ★ (24 ratings)
Users: 1,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a relatively low user base of 1,000 users and a below-average rating of 3.4 stars from only 24 reviews, which suggests limited adoption and mixed user satisfaction. The lack of developer information raises transparency concerns, making it difficult to verify the extension's legitimacy or contact support if issues arise. The WaybackMachine name suggests functionality related to the Internet Archive's Wayback Machine service, but without clear developer attribution, users cannot confirm if this is an official or authorized extension.

Concerns:

The tabs permission is concerning given the extension's apparent purpose. While WaybackMachine functionality typically only requires accessing the current page URL to redirect to archived versions, the tabs permission grants broader access to manipulate browser tabs and view tab information across all open tabs. This represents unnecessary permissions that exceed what would be expected for basic wayback functionality. The use of Manifest V2 also indicates outdated security practices, as newer extensions should migrate to the more secure Manifest V3 framework.

Recommendations:

Consider using the official Internet Archive Wayback Machine extension instead, which likely has better security practices and transparency. If you choose to use this extension, run it in a separate Chrome profile to limit potential security exposure. Monitor your browsing behavior for any unexpected tab manipulations or redirects to suspicious sites.

Findings

HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.