The extension has a solid user base of 100,000 users and maintains a good 4.5-star rating from 488 reviews, suggesting general user satisfaction. The developer appears to be the legitimate powerthesaurus.org website, which is a known thesaurus service. The extension is on version 4.5.3, indicating ongoing development and maintenance.
The extension's permissions are extremely broad for a thesaurus tool. The combination of all_urls host permissions with content script injection capabilities means it can access and modify any website you visit, not just when you're actively using the thesaurus feature. The clipboardWrite permission allows it to modify your clipboard contents, which could be exploited to inject malicious content. The unsafe WebAssembly execution policy is particularly concerning as it could hide malicious code. These permissions far exceed what would be necessary for a simple word lookup tool.
Given the critical risk level, consider running this extension in a separate Chrome profile dedicated to writing tasks only. Alternatively, use the powerthesaurus.org website directly instead of the extension to avoid the security risks. If you must use the extension, avoid using it while logged into sensitive accounts or handling confidential information. Monitor your clipboard contents after using the extension and consider using a different thesaurus tool with more limited permissions.
| https://chromewebstore.google.com/detail/power-thesaurus/hhnjkanigjoiglnlopahbbjdbfhkndjk/reviews | https://github.com/uuidjs/uuid#getrandomvalues-not-supported | |
| https://clients2.google.com/service/update2/crx | https://www.powerthesaurus.org | |
| https://api.powerthesaurus.org/ | https://www.google-analytics.com/ | |
| https://sentry.radyushin.com/ | https://www.powerthesaurus.org/ | |
| https://reactjs.org/docs/error-decoder.html?invariant= | http://www.w3.org/1999/xlink | |
| http://www.w3.org/XML/1998/namespace | http://www.w3.org/2000/svg | |
| http://www.w3.org/1998/Math/MathML | http://www.w3.org/1999/xhtml | |
| https://chrome.google.com/webstore/detail/apollo-client-developer-t/jdkknkkbebbapilgoeccciglkfbmbnfm | https://addons.mozilla.org/en-US/firefox/addon/apollo-developer-tools/ | |
| https://go.apollo.dev/c/err# | https://github.com/apollographql/invariant-packages | |
| https://github.com/benlesh/symbol-observable | http://www.example.com | |
| http://dogs.are.great | https://sentry.io/welcome/ | |
| https://www.apollographql.com/docs/react/basics/caching.html | https://github.com/apollographql/apollo-cache-persist#storage-providers | |
| https://formatjs.io/docs/tooling/babel-plugin | https://formatjs.io/docs/tooling/ts-transformer | |
| https://formatjs.io/docs/tooling/linter#enforce-id | https://formatjs.io/docs/react-intl#runtime-requirements | |
| https://formatjs.io/docs/react-intl/api#intlshape | https://formatjs.io/docs/getting-started/message-distribution | |
| https://7b7f9ed6e0ce3a44be470f1128edda52@sentry.radyushin.com/38 | https://addons.mozilla.org/en-US/firefox/addon/power-thesaurus/privacy/ | |
| https://www.powerthesaurus.org/_terms_conditions?source=extension |
{ "name": "__MSG_extensionName__", "icons": { "16": "icon16.plasmo.12e837fb.png", "32": "icon32.plasmo.468e3ee0.png", "48": "icon48.plasmo.a7a09c71.png", "64": "icon64.plasmo.6419b4b8.png", "128": "icon128.plasmo.5308f6ba.png" }, "action": { "default_icon": { "16": "icon16.plasmo.12e837fb.png", "32": "icon32.plasmo.468e3ee0.png", "48": "icon48.plasmo.a7a09c71.png", "64": "icon64.plasmo.6419b4b8.png", "128": "icon128.plasmo.5308f6ba.png" }, "default_popup": "popup.html" }, "author": "chrome@powerthesaurus.org", "version": "4.5.3", "background": { "service_worker": "static/background/index.js" }, "options_ui": { "page": "options.html", "open_in_tab": true }, "short_name": "__MSG_extensionShortName__", "update_url": "https://clients2.google.com/service/update2/crx", "description": "__MSG_extensionDescription__", "permissions": [ "scripting", "activeTab", "clipboardWrite", "contextMenus", "storage" ], "homepage_url": "https://www.powerthesaurus.org", "default_locale": "en", "content_scripts": [ { "js": [ "auth.da3477cc.js" ], "css": [], "run_at": "document_idle", "matches": [ "*://*.powerthesaurus.org/*" ] }, { "js": [ "keepalive.e2dc61cf.js" ], "css": [], "run_at": "document_start", "matches": [ "<all_urls>" ] }, { "js": [ "selectionIframe.20292347.js" ], "css": [], "run_at": "document_idle", "matches": [ "<all_urls>" ], "all_frames": true, "match_about_blank": true, "match_origin_as_fallback": true }, { "js": [ "selectionStart.c53f0e20.js" ], "css": [ "systemFonts.449fc473.css", "fonts.56096319.css" ], "run_at": "document_start", "matches": [ "<all_urls>" ] }, { "js": [ "selection.3fa02834.js" ], "css": [ "selection.7fb2fa62.css", "tabs/consent.b42bcbc0.css", "tabs/feedback.7e80d098.css" ], "run_at": "document_idle", "matches": [ "<all_urls>" ] } ], "host_permissions": [ "<all_urls>" ], "manifest_version": 3, "minimum_chrome_version": "105", "content_security_policy": { "extension_pages": "script-src 'self' 'wasm-unsafe-eval'; object-src 'self'; connect-src 'self' https://api.powerthesaurus.org/ https://www.google-analytics.com/ https://sentry.radyushin.com/ https://www.powerthesaurus.org/" }, "web_accessible_resources": [ { "matches": [ "<all_urls>" ], "resources": [ "fonts/roboto-latin-regular.woff2", "fonts/roboto-latin-500.woff2", "fonts/roboto-latin-700.woff2" ] }, { "matches": [ "<all_urls>" ], "resources": [ "selectionStart.570af368.css", "selectionStart.3ed704db.css", "selectionStart.15c0e00d.css", "selectionStart.eabaedbc.css", "selectionStart.a90784a2.css", "selectionStart.9bedcaa1.css", "selectionStart.4b0ccf6b.css", "selectionStart.5ecba23b.css", "selectionStart.6075cb05.css", "selectionStart.a72175f6.css", "selectionStart.7b5526f3.css", "selectionStart.3cbd11ea.css", "selectionStart.e0d33dc5.css", "selectionStart.4998255a.css", "selectionStart.ffad79ce.css", "selectionStart.02a908a7.css", "selectionStart.ad0a25ae.css", "selectionStart.25c369bf.css", "selectionStart.0aa95b8e.css", "selectionStart.6db7483a.css", "selectionStart.638a6441.css", "selectionStart.17bab65f.css", "selectionStart.bf870d27.css", "selectionStart.c7ae8adb.css", "selectionStart.efa0056d.css", "selectionStart.4ae2d9a9.css", "selectionStart.8c868fee.css", "selectionStart.94e21fe0.css", "selectionStart.29f821cf.css", "selectionStart.2202fc66.css", "selectionStart.7a6e70fe.css", "selectionStart.7b4079e6.css" ] } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.