CRX aminer
Extension icon

octolo

Version 0.1.1 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension lacks critical transparency indicators that would establish trust. There is no visible description, author information, developer details, user count, ratings, or reviews. The extension appears to be in early development (version 0.1.1) with minimal information available. The absence of basic metadata raises questions about the extension's legitimacy and purpose.

Concerns:
- Complete lack of description makes it impossible to understand the extension's intended functionality
- No author or developer information provided, eliminating accountability
- Unknown user base and rating history prevent community validation
- Uses outdated Manifest V2, which has weaker security protections
- The nativeMessaging permission allows communication with native applications on your computer, which could be concerning without knowing the extension's purpose
- contextMenus permission adds menu items but purpose is unclear without description
- Early version number suggests potentially unstable or incomplete software
Recommendations:

Given the complete lack of transparency and unknown functionality, avoid installing this extension. If you must use it for specific reasons, run it in a completely separate Chrome profile to isolate potential risks. The nativeMessaging permission is particularly concerning as it can interact with your system beyond the browser. Wait for more information about the developer, clear documentation of functionality, and user reviews before considering installation. Look for alternative extensions with established reputations and clear purposes instead.

Findings

MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.