CRX aminer

Starting analysis...

Extension icon

Bookmarks Backuper

Version 0.2.1.2 View in Chrome Web Store

Last scanned: 20 days ago | force re-scan

Extension Details

Developer: bookmarksbackuper.com
Rating: 3.9 ★ (45 ratings)
Users: 1,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a modest user base of 1,000 users with a decent 3.9-star rating from 45 reviews, suggesting some level of user satisfaction. The developer uses a domain-specific website (bookmarksbackuper.com) which indicates some investment in the project. The CSP policy is well-configured with strict security controls and only allows connections to legitimate services like Google APIs and Dropbox.
Concerns: The combination of identity and bookmarks permissions creates significant privacy risks. While bookmarks access is expected for a backup tool, the identity permission allows access to your Google account information, which goes beyond what's necessary for basic bookmark backup functionality. The extension could potentially access personal information and correlate it with your browsing patterns stored in bookmarks. The relatively small user base and lack of detailed developer information raise additional trust concerns.
Recommendations: Consider running this extension in a separate Chrome profile to isolate it from your main browsing data. Before installation, verify that the backup functionality truly requires Google account access - many bookmark backup tools can function without identity permissions by using local storage or manual export methods. Monitor the extension's network activity to ensure it only communicates with the declared services. Consider alternatives that require fewer permissions or have larger, more established user bases with transparent privacy policies.

Findings

HIGH
High-Risk Permission: bookmarks
This extension has the bookmarks permission. Can access and modify bookmarks. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.