CRX aminer
Extension icon

PDF Editor for Chrome:Edit, Fill, Sign, Print

Version 0.5.5 View in Chrome Web Store

Last scanned: about 6 hours ago

Extension Details

Developer: http://pdffiller.com/
Rating: 2.3 ★ (801 ratings)
Users: 200,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a substantial user base of 200,000 downloads, which indicates some level of adoption. However, the extremely low rating of 2.3 out of 5 stars from 801 reviews is a major red flag, suggesting widespread user dissatisfaction. The developer is associated with pdffiller.com, which is a legitimate PDF service company, providing some credibility to the extension's purpose.

Concerns:

The extension requests excessive permissions that far exceed what's necessary for basic PDF editing functionality. The combination of webRequest, webNavigation, tabs, and broad host permissions (*://*/*) creates a surveillance toolkit that can monitor and intercept all web traffic. Content scripts running on all protocols (http, https, ftp, file) indicate the extension can access virtually any content you view. The webRequest permission is particularly concerning as it allows modification of network requests, potentially enabling man-in-the-middle attacks or data theft.

Recommendations:

Given the critical risk level, avoid installing this extension entirely. The poor user ratings combined with excessive permissions suggest potential malicious behavior or poor security practices. If PDF editing is essential, consider using reputable alternatives with minimal permissions or web-based PDF editors that don't require browser extensions. If you must use this extension, run it in a completely isolated Chrome profile with no access to sensitive accounts or data.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.