CRX aminer

Starting analysis...

Extension icon

Functionize Architect

Version 10.7.89 View in Chrome Web Store

Last scanned: over 1 year ago | force re-scan

Extension Details

Developer: functionize.com
Rating: 4.8 ★ (21 ratings)
Size: 1.42MiB
Last Updated: April 1, 2025
Users: 100,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:
- The extension has over 100,000 users, indicating some level of popularity and trust.
- It is developed by a company (functionize.com) rather than an individual, which can provide more accountability.
- The relatively high rating of 4.8/5 from 21 reviews suggests most users find it useful and trustworthy.
Concerns:
- The extension requests an extremely broad set of permissions, including the ability to read clipboard data, control proxy settings, access all browser tabs and web requests, modify cookies, track web navigation, download files, debug other extensions, and inject scripts into any website.
- Many of these permissions pose significant privacy and security risks if misused, such as stealing sensitive data or credentials, modifying website content, or enabling remote code execution.
- The extension's content security policy allows unsafe WebAssembly execution, which could be leveraged for malicious purposes.
Recommendations:
- Exercise extreme caution when installing this extension, as it has sweeping capabilities that could compromise your privacy and security if it is not fully trustworthy.
- Consider running the extension in a separate browser profile or testing environment to isolate it from your main browsing activity.
- Closely monitor the extension's behavior and network activity for any suspicious actions.
- Periodically review the extension's permissions and revoke any unnecessary ones to reduce its potential attack surface.
- Ensure you have installed the extension from a reputable source, as malicious versions could be injected into unofficial distribution channels.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: clipboardRead
This extension has the clipboardRead permission. Can read clipboard content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: debugger
This extension has the debugger permission. Can debug and manipulate other extensions/apps. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: proxy
This extension has the proxy permission. Can control proxy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.