CRX aminer
Extension icon

C2 Password

Version 2.30.17 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Rating: 4.6 ★ (286 ratings)
Users: 30,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: The extension has a decent user base of 30,000 users and a solid 4.6-star rating from 286 reviews, suggesting legitimate functionality. However, the lack of clear developer information and company details raises transparency concerns. The name "C2 Password" suggests it's a password management tool, which would typically require extensive permissions.
Concerns: The extension requests an extremely broad set of permissions that far exceed what most password managers need. The privacy permission allows modification of browser privacy settings, which is unusual for password tools. The webRequest permission enables interception and modification of all web traffic, creating potential for data theft. The <all_urls> host permissions and content script injection capabilities mean this extension can access and modify any website you visit. The webNavigation permission allows comprehensive tracking of your browsing behavior. These permissions combined create a perfect storm for potential surveillance or data harvesting.
Recommendations: Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile with minimal sensitive data and limit browsing to essential sites only. Consider well-established password managers like Bitwarden, 1Password, or Dashlane instead, which typically require fewer invasive permissions. Before proceeding, research the developer's identity and reputation thoroughly, as the lack of clear attribution is concerning for security software.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: privacy
This extension has the privacy permission. Can modify privacy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.