CRX aminer

Starting analysis...

Extension icon

Senso Client

Version 2.0.5.5 View in Chrome Web Store

Last scanned: about 1 year ago | force re-scan

Extension Details

Rating: 1.3 ★ (56 ratings)

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has extremely poor trust indicators with only a 1.3-star rating from 56 reviews, suggesting widespread user dissatisfaction. The lack of clear author information and developer details raises transparency concerns. The name "Senso Client" suggests it may be enterprise monitoring software, but without proper documentation or company backing, its legitimacy is questionable.

Concerns:

This extension exhibits characteristics of potentially malicious software with an extensive collection of invasive permissions. The combination of webRequest, webRequestBlocking, and all_urls permissions allows complete interception and modification of all web traffic. The management permission enables control over other extensions, while desktopCapture can record screen activity. The identity and cookies permissions provide access to personal authentication data. The unsafe-eval CSP policy creates additional security vulnerabilities. The enterprise-level permissions suggest this may be designed for corporate surveillance rather than legitimate user functionality.

Recommendations:

Do not install this extension under any circumstances given the critical risk level and poor user ratings. If this extension is required by your organization, immediately contact your IT security team to verify its legitimacy and necessity. If already installed, remove it immediately and run a security scan. Consider that this extension may be monitoring all your browsing activity, potentially capturing sensitive information including passwords and personal data.

Findings

HIGH
Dangerous Permission Combination: webRequest + webRequestBlocking
This extension can intercept, modify, and block web requests in real-time. This combination could be used to modify sensitive web traffic or steal data.
HIGH
High-Risk Permission: <all_urls>
This extension has the <all_urls> permission. Can access all websites and their content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequestBlocking
This extension has the webRequestBlocking permission. Can block and modify web requests in real-time. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe JavaScript Evaluation
This extension's Content Security Policy allows 'unsafe-eval', which permits dynamic JavaScript code execution using eval() and similar functions. This is a significant security risk as it could allow execution of malicious code.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.