CRX aminer
Extension icon

TabFloater: Picture-in-Picture for any tab!

Version 2.0.0 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Developer: tabfloater.io
Rating: 3.7 ★ (69 ratings)
Users: 6,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a moderate user base of 6,000 users with a decent 3.7-star rating from 69 reviews, suggesting some level of community validation. The developer uses a professional domain (tabfloater.io) which adds credibility. The picture-in-picture functionality described aligns with the extension's stated purpose of floating tabs.

Concerns:

The combination of tabs permission with broad host permissions (<all_urls>) creates significant privacy and security risks. The extension can access and manipulate all browser tabs while having unrestricted access to every website you visit. The nativeMessaging permission allows communication with external applications on your system, which could potentially be exploited. The offscreen permission enables background processing that may not be transparent to users. While storage and notifications permissions are reasonable for the functionality, the overall permission set is quite expansive for a tab floating utility.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to non-sensitive browsing activities. Regularly review what tabs you're floating and avoid using it with sensitive websites like banking or personal accounts. Monitor your system for any unexpected native applications that might be communicating with the extension. Given the broad permissions, consider alternative picture-in-picture solutions with more limited scope if available. Keep the extension updated and periodically review its behavior and any changes in permissions.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.