CRX aminer
Extension icon

Chessvision.ai Chess Position Scanner

Version 3.8.1 View in Chrome Web Store

Last scanned: 15 days ago | force re-scan

Extension Details

Developer: SOFTWARE PAWEŁ KACPRZAK
Rating: 4.6 ★ (737 ratings)
Users: 100,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a solid user base of 100,000 users with a strong 4.6-star rating from 737 reviews, indicating positive user experiences. The specific purpose of scanning chess positions is clearly defined and legitimate. The developer is identified as SOFTWARE PAWEŁ KACPRZAK, providing some accountability.

Concerns:

The primary concern is the broad host permissions (*://app.chessvision.ai/*) which, while specific to the developer's domain, still represents elevated access. The combination of activeTab, storage, and scripting permissions creates a capability set that could potentially access and store data from web pages. However, these permissions align reasonably well with the extension's stated purpose of scanning chess positions from various chess websites.

The security analysis flagged the host permissions as high-risk, but this appears to be limited to the developer's own domain rather than all websites, which reduces the actual risk significantly. The activeTab permission is appropriate for a tool that needs to analyze chess positions on the current page.

Recommendations:

This extension appears legitimate for its intended purpose. Users should ensure they only use it on trusted chess websites. Consider running it in a separate Chrome profile if you're particularly security-conscious, though this may be unnecessary given the specific domain restrictions and positive user feedback. Monitor for any unusual behavior or requests for additional permissions in future updates.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.