CRX aminer
Extension icon

Locale Switcher

Version 1.3.1 View in Chrome Web Store

Last scanned: about 14 hours ago

Extension Details

Rating: 4.4 ★ (77 ratings)
Users: 50,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a solid user base of 50,000 users and maintains a good rating of 4.4 stars from 77 reviews, indicating general user satisfaction. The name "Locale Switcher" suggests a legitimate utility function for changing language/region settings. However, the lack of visible developer information reduces transparency and accountability.

Concerns:

The primary concern is the broad content script injection capability across all URLs, which creates significant potential for data exposure. While the extension's stated purpose may justify accessing websites to modify locale settings, this permission grants access to all website content including sensitive information like passwords, personal data, and financial details. The storage permission, while necessary for remembering user preferences, could potentially be used to collect and store browsing data. The activeTab permission is appropriately scoped for the extension's functionality.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to non-sensitive browsing activities. Before installation, verify the extension's behavior by checking recent reviews for any reports of suspicious activity. Monitor your browsing sessions after installation for any unexpected behavior. If you only need locale switching for specific websites, consider looking for alternatives with more restricted permissions. Given the broad access requirements, only install if you specifically need this functionality and trust the developer despite the limited transparency.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.