CRX aminer
Extension icon

Salesforce Custom Label Manager

Version 1.2.0 View in Chrome Web Store

Last scanned: about 15 hours ago

Extension Details

Rating: 5.0 ★ (2 ratings)
Users: 56

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has very limited adoption with only 56 users and just 2 ratings, making it difficult to assess reliability through community feedback. While it maintains a perfect 5.0 rating, the small sample size is not statistically significant. The lack of visible developer information raises transparency concerns, and the extension appears to be relatively new or niche within the Salesforce ecosystem.

Concerns:

The cookies permission is particularly concerning for a custom label management tool, as this functionality seems unnecessary for managing Salesforce labels. The broad host permissions covering all Salesforce and Force.com domains create an extensive attack surface that goes beyond what would typically be required for label management. The combination of cookie access and broad domain permissions could enable session hijacking or unauthorized data access across multiple Salesforce organizations. The activeTab permission, while less critical, adds another layer of potential access that may not be essential for the stated functionality.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to Salesforce development work to isolate potential risks. Before installation, verify the extension's necessity - many Salesforce label management tasks can be accomplished through native Salesforce tools or more established extensions with better track records. If you must use this extension, monitor your Salesforce sessions carefully and log out completely when finished. Consider reaching out to the developer for clarification on why cookie permissions are required for label management functionality.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.