CRX aminer
Extension icon

WhatFont

Version 3.2.0 View in Chrome Web Store

Last scanned: about 7 hours ago

Extension Details

Developer: chengyinliu.com
Rating: 4.0 ★ (2K ratings)
Users: 3,000,000

Context-Aware Verdict

LOW
Overall Risk
Trust Factors:

WhatFont is a well-established font identification tool with an impressive 3 million users and a solid 4.0-star rating from 2,000 reviews. The extension serves a clear, legitimate purpose - helping designers and developers identify fonts on web pages. The developer appears to maintain the extension actively, having updated it to Manifest V3, which demonstrates commitment to modern security standards.

Concerns:

The extension requests activeTab and scripting permissions, which are necessary for its core functionality of analyzing fonts on web pages. While these permissions are appropriate for a font identification tool, they do allow the extension to access and modify content on the currently active tab when the user clicks the extension icon. The scripting permission enables code injection into web pages, which could theoretically be misused if the extension were compromised.

Recommendations:

This extension presents minimal risk for most users. The permissions align well with its stated purpose, and the large user base suggests it's trustworthy. However, security-conscious users should be aware that the extension can access page content when activated. For users working with sensitive information, consider using WhatFont only on non-sensitive websites or in a separate Chrome profile dedicated to design work. The extension's popularity and longevity in the Chrome Web Store provide additional confidence in its legitimacy.

Findings

MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.