CRX aminer
Extension icon

Rabatta

Version 11.7.7 View in Chrome Web Store

Last scanned: 7 months ago | force re-scan

Extension Details

Developer: rabatta.app
Rating: 4.2 ★ (44 ratings)
Size: 2.02MiB
Last Updated: May 29, 2025
Users: 100,000
Developer Info: Rabatta ApSKridtsløjfen 6, sal 2th Aalborg 9000 DK

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:
- The extension has a relatively high number of users (100,000), which could indicate some level of trust.
- However, the developer information is limited, and there is no clear indication of a reputable company behind the extension.
Concerns:
- The extension requests broad host permissions (*://*/*) and content script injection (*://*/*; https://*/search*), allowing it to access and modify any website. These permissions are unnecessary for the stated purpose of the extension and pose significant privacy and security risks.
- The "storage" permission allows the extension to store data locally, which could potentially be used to store sensitive information without the user's knowledge.
- The combination of broad permissions and the lack of clear information about the developer raises concerns about the extension's intentions and potential for misuse.
Recommendations:
- Exercise caution when installing this extension, as the broad permissions and lack of transparency about the developer's intentions raise significant privacy and security concerns.
- If you decide to use the extension, consider running it in a separate browser profile or a sandboxed environment to limit potential risks.
- Regularly review the extension's permissions and activity, and uninstall it if you notice any suspicious behavior or if the extension requests additional permissions beyond what is necessary for its stated purpose.
- Consider using alternative extensions from reputable developers that request only the necessary permissions for their intended functionality.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.