CRX aminer
Extension icon

Hoverflow

Version 1.2.5 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Developer: Moonstop Software Ltd
Rating: 4.7 ★ (33 ratings)
Users: 1,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors: The extension has a solid 4.7-star rating from 33 reviews and is developed by Moonstop Software Ltd, which suggests some level of legitimacy. However, the relatively low user count of 1,000 users indicates limited adoption, which could mean less community vetting. The lack of a clear description makes it difficult to assess the extension's intended purpose and whether its permissions are justified.
Concerns: The most significant concern is the broad host permissions for Wikipedia domains, which seems excessive unless the extension specifically enhances Wikipedia functionality. The combination of scripting, activeTab, and declarativeNetRequestWithHostAccess permissions creates a powerful toolkit that could potentially be misused. The storage permission, while common, adds to the overall permission footprint. The missing description is particularly concerning as users cannot properly evaluate whether the requested permissions align with the extension's stated functionality.
Recommendations: Given the medium risk level, consider running this extension in a separate Chrome profile to isolate potential security risks from your main browsing environment. Before installation, research the extension's actual purpose through user reviews or the developer's website to determine if the Wikipedia-focused permissions are appropriate. Monitor the extension's behavior after installation and remove it if you notice any unexpected activity. Consider looking for alternative extensions with clearer descriptions and more transparent permission usage if this extension's purpose remains unclear.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.