CRX aminer
Extension icon

Getro: Contact Sync & Network Management

Version 3.3.0 View in Chrome Web Store

Last scanned: about 19 hours ago

Extension Details

Developer: getro.com
Rating: 5.0 ★ (11 ratings)
Users: 1,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a perfect 5.0 rating but with only 11 reviews, which is insufficient to establish reliability. With just 1,000 users, it lacks the widespread adoption that typically indicates trustworthiness. The developer is associated with getro.com, which appears to be a legitimate networking platform, providing some credibility. However, the small user base and limited review history make it difficult to fully assess the developer's reputation.

Concerns:

The extension requests excessive permissions that far exceed what's necessary for contact sync and network management. The management permission is particularly concerning as it allows control over other extensions, which is completely unrelated to the stated functionality. The webNavigation permission enables comprehensive browsing tracking beyond LinkedIn. The cookies permission combined with broad host permissions creates significant privacy risks. The extension's access to LinkedIn data, while expected, combined with these other permissions creates a dangerous combination for data harvesting.

Recommendations:

Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile with minimal sensitive data and no other extensions installed. Consider alternative contact management solutions with more limited permissions. Monitor your LinkedIn account closely for any unusual activity if you proceed with installation. The risk-to-benefit ratio appears unfavorable given the extensive permissions requested for basic contact sync functionality.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://www.linkedin.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.