CRX aminer

Version 1.1.15 View in Chrome Web Store

Last scanned: 5 days ago | force re-scan

Extension Details

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension appears to be designed for Caixa Econômica Federal, a major Brazilian government bank, based on the domain permissions. However, critical trust indicators are missing - there's no extension name, author information, user count, or ratings provided, making it impossible to verify legitimacy or assess community trust.

Concerns:

The extension requests native messaging capabilities, which allows communication with programs installed on your computer - a powerful permission that could be exploited. The unlimited storage permission combined with regular storage access means it can accumulate vast amounts of data on your device. The extension targets specific banking domains (caixa.gov.br and related subdomains) plus localhost, which could indicate legitimate banking integration but also presents risks if the extension is malicious. The use of Manifest V2 provides fewer security protections compared to the newer V3 standard.

Recommendations:

Only install this extension if you're certain it's the official Caixa banking extension and you actively use their online banking services. Verify the extension's authenticity through official Caixa channels before installation. Consider running it in a separate Chrome profile dedicated to banking activities to isolate potential risks. Monitor your system for unusual behavior after installation, particularly any unexpected native application launches or excessive data storage usage.

Findings

MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.