CRX aminer
Extension icon

Gmail Theme Sync & Control

Version 1.1.1 View in Chrome Web Store

Last scanned: about 9 hours ago

Extension Details

Rating: 5.0 ★ (1 rating)
Users: 111

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has very limited adoption with only 111 users and a single 5-star rating, making it difficult to assess reliability through community feedback. The lack of developer information and company details raises transparency concerns. However, the specific focus on Gmail theme functionality appears legitimate given its targeted host permissions.

Concerns:

The primary concern is the broad host permissions for mail.google.com, which grants extensive access to your entire Gmail account including emails, contacts, and personal data. While the activeTab and storage permissions are reasonable for theme management, the combination allows the extension to potentially access, modify, or exfiltrate sensitive email content. The low user base means less community vetting, and the absence of developer identification makes accountability unclear.

Recommendations:

Given the medium risk level, consider running this extension in a separate Chrome profile dedicated to Gmail if you must use it. This isolates potential security risks from your main browsing profile. Before installation, verify that theme synchronization truly requires such broad Gmail access - many theme extensions function with more limited permissions. Monitor the extension's behavior after installation and remove it immediately if you notice any unusual activity. Consider waiting for the extension to gain more users and reviews before trusting it with access to your Gmail account.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://mail.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.