CRX aminer
Extension icon

TwExportly: Export Tweets From Any Account

Version 2.29 View in Chrome Web Store

Last scanned: about 8 hours ago

Extension Details

Developer: 100xtools.com
Rating: 3.2 ★ (20 ratings)
Users: 10,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a moderate user base of 10,000 users, which suggests some level of adoption. However, the relatively low rating of 3.2 out of 5 stars with only 20 reviews raises concerns about user satisfaction and potential issues. The developer 100xtools.com appears to be a tools-focused company, but limited information about their reputation makes it difficult to assess trustworthiness fully.

Concerns:

The webRequest permission is particularly concerning for a tweet export tool, as this allows the extension to intercept and potentially modify all web traffic. This capability far exceeds what would be necessary for simply exporting tweets. The broad host permissions, while limited to Twitter/X domains, still grant extensive access to user activity on these platforms. The combination of these permissions creates potential for data harvesting beyond the stated purpose of tweet export.

Recommendations:

Given the high-risk permissions that seem excessive for the extension's stated functionality, consider running this extension in a separate Chrome profile to isolate it from your main browsing activities. Before installation, verify that tweet export functionality truly requires webRequest permissions by checking if alternative extensions with more limited permissions exist. Monitor the extension's behavior closely and remove it immediately if you notice any suspicious network activity or unexpected data requests.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: *://*.twitter.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.