CRX aminer
Extension icon

GitHub User Languages

Version 1.1.0 View in Chrome Web Store

Last scanned: about 6 hours ago

Extension Details

Developer: freyama.de
Rating: 5.0 ★ (3 ratings)
Users: 1,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a perfect 5.0 rating, though based on only 3 reviews, which limits reliability. With 1,000 users, it has modest adoption but lacks widespread validation. The developer domain "freyama.de" appears to be an individual developer rather than an established company, which reduces institutional trust. The extension's purpose of displaying GitHub user languages is legitimate and aligns with its requested permissions.

Concerns:

The extension requests access to GitHub's API and a third-party repository for color data, which is appropriate for its functionality but creates dependency on external services. The storage permission allows local data retention, which could potentially store user information or browsing patterns. The content script injection on all GitHub pages provides broad access to user activity on the platform. The limited number of reviews makes it difficult to assess real-world performance and trustworthiness.

Recommendations:

Given the medium risk level, consider running this extension in a separate Chrome profile if you frequently work with sensitive GitHub repositories or organizational accounts. Monitor what data the extension might be storing locally through Chrome's developer tools. Verify the extension's behavior matches its stated purpose of showing programming languages. Consider whether the functionality provided justifies the GitHub access permissions, especially if you work with private repositories.

Findings

MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://api.github.com/, https://raw.githubusercontent.com/ozh/github-colors/master/colors.json. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.