CRX aminer
Extension icon

Oink for Influencers

Version 6.6.9 View in Chrome Web Store

Last scanned: about 7 hours ago

Extension Details

Developer: https://thelaststopreviewshop.com/
Rating: 5.0 ★ (21 ratings)
Users: 6,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a perfect 5.0 rating but with only 21 reviews, which is insufficient for reliable assessment. With 6,000 users, it has moderate adoption but lacks transparency - no clear company information is provided, only a website URL. The developer identity is unclear, and the extension targets influencers working with Amazon's affiliate program, which could be legitimate but requires careful scrutiny.

Concerns:

The extension requests extremely broad permissions that far exceed what's necessary for typical influencer tools. The combination of tabs, downloads, and scripting permissions across multiple major platforms (Amazon, Facebook, Instagram, YouTube) creates significant attack surface. The unsafe WebAssembly execution policy is particularly concerning as it could hide malicious code. Access to sensitive domains like Facebook Business and Instagram Direct messages raises privacy concerns. The broad host permissions essentially give this extension access to monitor and manipulate your entire browsing experience across major e-commerce and social platforms.

Recommendations:

Given the critical risk level, avoid installing this extension on your main browser profile. If you must use it, create a dedicated Chrome profile specifically for influencer activities and limit your browsing to only necessary sites while using it. Regularly monitor your Amazon affiliate account and social media accounts for unauthorized activity. Consider alternative influencer tools with more limited permissions. The risk-to-benefit ratio appears unfavorable unless this tool provides absolutely essential functionality you cannot obtain elsewhere.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: *://*.amazon.com/*, https://www.amazon.co.uk/*, https://www.amazon.ca/*, https://www.amazon.com.au/*, https://affiliate-program.amazon.com/*, https://m.media-amazon.com/*, *://*.facebook.com/*, *://business.facebook.com/*, *://*.instagram.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.