CRX aminer
Extension icon

Hoverflow

Version 1.2.5 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Developer: Moonstop Software Ltd
Rating: 4.7 ★ (33 ratings)
Users: 1,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a solid 4.7-star rating from 33 reviews and is developed by Moonstop Software Ltd, which suggests some level of legitimacy. However, with only 1,000 users, it has a relatively small user base that limits the ability to assess its reputation through widespread adoption. The lack of a clear description makes it difficult to understand the extension's intended purpose and functionality.

Concerns:

The primary concern is the broad host permissions for Wikipedia domains, which seems excessive without understanding what the extension actually does. The combination of scripting permissions with declarativeNetRequestWithHostAccess could potentially allow the extension to modify web requests and inject scripts on Wikipedia pages. The storage permission, while common, adds to the risk profile when combined with the other permissions. The missing description is particularly concerning as users cannot properly evaluate whether the requested permissions are justified for the extension's stated purpose.

Recommendations:

Given the medium risk level and unclear functionality, consider running this extension in a separate Chrome profile to isolate potential security risks. Before installation, try to research the extension's actual purpose through user reviews or the developer's website. Monitor the extension's behavior on Wikipedia pages and be cautious about any unexpected modifications to page content or functionality. Consider whether you actually need this extension's functionality, especially given the broad permissions it requests.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.