CRX aminer
Extension icon

BizflyCloud Callcenter 3

Version 3.0.2 View in Chrome Web Store

Last scanned: 2 days ago | force re-scan

Extension Details

Rating: 4.8 ★
Users: 483

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a small user base of only 483 users and a high rating of 4.8, which suggests positive user experience among those who use it. However, the limited adoption raises questions about widespread testing and validation. The extension appears to be associated with BizflyCloud, a Vietnamese cloud service provider, and is designed for call center functionality. The lack of detailed developer information and missing last updated date reduces transparency.

Concerns:

The extension requests extremely broad permissions that far exceed what's typically needed for call center functionality. The combination of tabs permission, universal host permissions (http://*/* and https://*/*), and content script injection across all URLs creates a powerful surveillance capability. These permissions would allow the extension to monitor all browsing activity, access sensitive data on any website, and potentially intercept credentials or personal information. The offscreen permission adds another layer of background processing capability that could be misused.

Recommendations:

Given the high-risk nature of this extension, install it only in a separate Chrome profile dedicated to call center work. Limit this profile's access to sensitive websites and personal accounts. Regularly audit the extension's behavior and consider network monitoring to detect any unexpected data transmission. Only install if absolutely necessary for business operations, and explore alternative call center solutions with more restrictive permissions. Contact BizflyCloud directly to verify the extension's legitimacy and understand why such broad permissions are required.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.