CRX aminer
Extension icon

Katalon Studio Recording Engine

Version 1.0.14 View in Chrome Web Store

Last scanned: 1 day ago | force re-scan

Extension Details

Rating: 2.7 ★
Users: 910

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: This extension has concerning trust indicators. With only 910 users and a poor 2.7-star rating, it shows limited adoption and user satisfaction. The extension is associated with Katalon Studio, a legitimate test automation platform, which provides some credibility. However, the low user count and rating suggest potential issues with functionality or user experience.
Concerns: The extension's permissions are extremely broad and concerning for its stated purpose as a recording engine. The combination of cookies, tabs, and webNavigation permissions with all_urls host access creates a powerful surveillance capability. The WebSocket connections to localhost suggest it communicates with local Katalon software, but the broad web access permissions far exceed what's necessary for basic test recording. Content script injection across all websites poses significant security risks, as it could potentially capture sensitive data including login credentials, personal information, and browsing behavior.
Recommendations: Given the critical risk level, avoid installing this extension unless absolutely necessary for Katalon Studio automation work. If required, run it in a completely separate Chrome profile dedicated solely to testing activities, never use it for personal browsing, and disable it immediately after testing sessions. Consider alternative test automation tools that don't require such invasive browser permissions. Regularly audit what data the extension might be collecting and ensure your Katalon Studio installation is from official sources and properly secured.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.