CRX aminer
Extension icon

AppSheet Toolbox

Version 4.0090 View in Chrome Web Store

Last scanned: 13 days ago | force re-scan

Extension Details

Developer: appsheettraining.com
Rating: 4.0 ★ (52 ratings)
Size: 722KiB
Last Updated: December 14, 2023
Users: 20,000
Developer Info: Qrew LLC1701 Southwest Parkway 108 College Station, TX 77840 US

Context-Aware Verdict

MEDIUM
Risk Level
Trust Factors:
- The extension is developed by a legitimate company, Qrew LLC, which provides AppSheet services.
- It has a decent number of users (20,000) and a relatively good rating (4.0/5.0 from 52 reviews), indicating some level of trust from the user community.
- The description suggests it is a toolbox extension for AppSheet, which aligns with the permissions and host access requested.
Concerns:
- The "tabs" permission allows the extension to access and manipulate browser tabs, which could potentially be misused for privacy violations or security compromises.
- The broad host permissions allow the extension to access many websites, raising concerns about potential data theft or tracking of browsing activity.
- The extension requests access to sensitive domains, which could be a privacy risk if the extension is not trustworthy.
Recommendations:
- Review the extension's privacy policy and terms of service to understand how user data is handled and what the extension does with the requested permissions.
- Consider running the extension in a separate browser profile or a sandboxed environment to isolate it from your main browsing activity.
- Monitor the extension's behavior and uninstall it if you notice any suspicious activity or privacy violations.
- Keep the extension updated to the latest version to ensure any security vulnerabilities are patched.
- If you have concerns about the extension's legitimacy or behavior, consider contacting the developer or reporting the extension to the Chrome Web Store.

Security Analysis

HIGH
Overall Risk
Based on 4 total findings, ranked without considering overall context, including 2 high-risk and 2 medium-risk findings.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://support.google.com/appsheet/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.