CRX aminer
Extension icon

Wappalyzer - Technology profiler

Version 6.12.2 View in Chrome Web Store

Last scanned: about 9 hours ago

Extension Details

Developer: wappalyzer.com
Rating: 4.6 ★ (2K ratings)
Users: 3,000,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

Wappalyzer is a well-established technology profiling tool with 3 million users and a strong 4.6-star rating from 2,000 reviews. The extension is developed by wappalyzer.com, a legitimate company known for website technology analysis. The high user base and positive ratings suggest it's a trusted tool in the web development and security analysis community.

Concerns:

The extension's permissions are extensive and powerful, which creates significant security risks despite its legitimate purpose. The combination of cookies, webRequest, tabs permissions with broad host access (all HTTP/HTTPS sites) means this extension can monitor, intercept, and potentially modify all web traffic. While these permissions are necessary for technology profiling, they also create opportunities for data collection, tracking, and potential misuse. The ability to access cookies across all sites is particularly concerning from a privacy perspective.

Recommendations:

Given the critical risk level but legitimate use case, consider running this extension in a dedicated Chrome profile used only for web development or security analysis work. Avoid using it in your primary browsing profile where you access sensitive sites like banking or personal accounts. Regularly review the extension's privacy policy and consider alternatives with more limited scope if you only need basic technology detection. Monitor for any unusual network activity when the extension is active.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.