CRX aminer
Extension icon

Hoverflow

Version 1.2.5 View in Chrome Web Store

Last scanned: about 7 hours ago

Extension Details

Developer: Moonstop Software Ltd
Rating: 4.7 ★ (33 ratings)
Users: 2,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a solid 4.7-star rating from 33 reviews and is developed by Moonstop Software Ltd, which suggests some level of legitimacy. However, with only 2,000 users, it has a relatively small user base that limits community vetting. The lack of a clear description makes it difficult to assess the extension's intended purpose and whether its permissions are justified.

Concerns:

The primary concern is the broad host permissions for Wikipedia domains combined with declarativeNetRequestWithHostAccess, which allows the extension to modify network requests and access content across all Wikipedia pages. Without knowing the extension's specific function, these permissions appear potentially excessive. The storage permission allows data collection and retention, while activeTab provides access to whatever page you're viewing when the extension is activated. The missing description is particularly concerning as it prevents users from understanding what they're installing.

Recommendations:

Given the medium risk level and unclear purpose, consider running this extension in a separate Chrome profile to isolate it from your main browsing activities. Before installation, try to research the extension's actual functionality through user reviews or the developer's website. Monitor your Wikipedia browsing for any unusual behavior. If the extension's purpose doesn't clearly justify Wikipedia access and network request modification, consider finding an alternative with more transparent functionality and narrower permissions.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.