CRX aminer
Extension icon

IP Whois & Flags Chrome & Websites Rating

Version 4.0 View in Chrome Web Store

Last scanned: about 7 hours ago

Extension Details

Developer: http://myip.ms/
Rating: 4.4 ★ (651 ratings)
Users: 30,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a moderate user base of 30,000 users and a solid 4.4-star rating from 651 reviews, which suggests some level of user satisfaction. The developer operates from myip.ms, which appears to be a legitimate IP lookup service. However, the extension uses the older Manifest V2, indicating it hasn't been updated to meet newer security standards.

Concerns:

The extension's permission set is extremely broad and concerning for what should be a simple IP lookup tool. The combination of webRequest, webRequestBlocking, tabs, and all_urls permissions creates a dangerous scenario where the extension can intercept, modify, and block all web traffic across every website you visit. This level of access far exceeds what's necessary for displaying IP information and website ratings. The extension essentially has the capability to act as a man-in-the-middle for all your browsing activity, potentially capturing sensitive data like login credentials, personal information, or financial details.

Recommendations:

Given the critical risk level, avoid installing this extension on your main browser profile. If you must use it, create a separate Chrome profile specifically for this extension and only use it for non-sensitive browsing. Consider alternative IP lookup tools that require fewer permissions or use web-based services instead. The broad permissions combined with the ability to modify web requests makes this extension a significant security risk that outweighs its utility.

Findings

HIGH
Dangerous Permission Combination: webRequest + webRequestBlocking
This extension can intercept, modify, and block web requests in real-time. This combination could be used to modify sensitive web traffic or steal data.
HIGH
High-Risk Permission: <all_urls>
This extension has the <all_urls> permission. Can access all websites and their content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequestBlocking
This extension has the webRequestBlocking permission. Can block and modify web requests in real-time. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.