CRX aminer
Extension icon

Refined GitHub

Version 26.5.24 View in Chrome Web Store

Last scanned: about 1 hour ago

Extension Details

Developer: https://refined-github.github.io/
Rating: 4.8 ★ (264 ratings)
Users: 100,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

Refined GitHub is a well-established open-source extension with strong community trust indicators. With 100,000 users and an excellent 4.8-star rating from 264 reviews, it demonstrates solid user satisfaction. The extension has a dedicated website and appears to be actively maintained. The open-source nature allows for community code review, which enhances transparency and trustworthiness.

Concerns:

The primary concern is the broad host permissions for GitHub domains, though this is actually appropriate given the extension's purpose of enhancing GitHub's interface. The storage permission allows local data retention, which could include GitHub-related preferences or cached data. The contextMenus and activeTab permissions enable interface modifications but are reasonable for a GitHub enhancement tool. The scripting permission allows code injection into GitHub pages, which is necessary for the extension's functionality but represents the highest risk vector.

Recommendations:

This extension appears legitimate and purposeful for GitHub users. The permissions align well with its stated functionality of improving GitHub's user interface. Since it only accesses GitHub domains rather than all websites, the risk is contained to those specific sites. Users who frequently use GitHub would likely benefit from this extension. However, users concerned about data privacy should review what information the extension might store locally. Running in a separate profile is unnecessary unless you have specific security requirements for GitHub usage.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://github.com/*, https://api.github.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.