CRX aminer
Extension icon

Oracle Eloqua Sales Tools

Version 3.0.0 View in Chrome Web Store

Last scanned: about 6 hours ago

Extension Details

Rating: 4.7 ★ (25 ratings)
Users: 916

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension appears to be a legitimate business tool from Oracle for their Eloqua marketing platform, which adds some credibility. The rating of 4.7 from 25 reviews is positive, though the small user base of 916 suggests limited adoption. However, the lack of clear developer information and missing last updated date raises transparency concerns.

Concerns:

The extension requests extremely broad permissions that extend far beyond what would be expected for Eloqua-specific functionality. The content scripts permission for all HTTP and HTTPS sites (http://*/*, https://*/*) is particularly concerning as it allows the extension to inject code into every website you visit. While the host permissions are appropriately scoped to Eloqua domains, the combination of tabs, cookies, and scripting permissions across all websites creates significant privacy and security risks. The broad content script access could potentially be exploited to capture sensitive information from banking sites, email, or other personal accounts.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated only to Eloqua-related work to limit exposure. Before installation, verify this is the official Oracle extension through Oracle's support channels. Monitor the extension's behavior and disable it when not actively using Eloqua. Given the broad permissions, only install if Eloqua functionality is business-critical and you trust Oracle's security practices completely.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.