CRX aminer
Extension icon

Tipli: Cashback și cupoane de reducere

Version 3.1.9 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Developer: Tipli s.r.o.
Rating: 4.2 ★ (25 ratings)
Users: 10,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a moderate user base of 10,000 users and a decent rating of 4.2/5 from 25 reviews, suggesting some level of user satisfaction. The developer is identified as Tipli s.r.o., which appears to be a legitimate company offering cashback and coupon services. The extension's purpose aligns with its name and description for providing cashback and discount coupons.

Concerns:

The extension presents significant security risks due to its extensive permissions. The combination of broad host permissions (*://*/*) and content script injection across all URLs creates a powerful surveillance capability that far exceeds what's necessary for a cashback service. The webRequest permission allows interception and modification of all web traffic, which could be exploited for data harvesting or man-in-the-middle attacks. The unlimited storage permission raises concerns about potential data hoarding. While the extension targets specific shopping and search sites, the broad permissions suggest it can monitor all browsing activity.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to shopping activities only. Regularly review what data the extension collects and stores. Monitor your browsing behavior for any unusual activity. Consider alternative cashback services with more limited permissions. If you must use this extension, avoid accessing sensitive sites (banking, email, social media) while it's active. Regularly check for updates and review any permission changes.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.