CRX aminer
Extension icon

Flonnect Enterprise: Video, Steps & Bug Reports

Version 1.1.5 View in Chrome Web Store

Last scanned: about 1 hour ago

Extension Details

Developer: flonnect.com
Rating: 4.2 ★
Users: 28

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has extremely low adoption with only 28 users despite being available for some time, which raises significant red flags. While it maintains a 4.2 rating, the small user base makes this less meaningful. The developer domain flonnect.com suggests a legitimate business purpose for enterprise video and bug reporting functionality. However, the combination of minimal adoption and extensive permissions creates substantial concern.

Concerns:

The extension requests an excessive array of high-risk permissions that far exceed what would be necessary for basic video recording and bug reporting. The ability to capture desktop content, intercept all web requests, track navigation across all websites, and inject scripts into every page creates a perfect surveillance toolkit. The broad host permissions and content script injection capabilities mean this extension can access sensitive data on banking sites, email platforms, and any other website you visit. The webRequest permission allows it to potentially modify or intercept secure communications.

Recommendations:

Do not install this extension in your primary browser profile. If you must use it for legitimate enterprise purposes, create a completely separate Chrome profile dedicated solely to this tool and avoid accessing any sensitive websites while using it. Verify directly with your IT department that this specific extension is required and approved. Consider whether the business functionality could be achieved through less invasive alternatives. The risk-to-benefit ratio appears heavily skewed toward risk given the extensive surveillance capabilities versus the stated purpose.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.