CRX aminer
Extension icon

Track Your Order

Version 1.0.3 View in Chrome Web Store

Last scanned: 1 day ago | force re-scan

Extension Details

Rating: 1.0 ★ (1 rating)
Users: 6,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has several concerning trust indicators. With only 6,000 users and a critically low 1.0-star rating based on just one review, user satisfaction appears extremely poor. The lack of author and developer information raises transparency concerns, making it difficult to verify the extension's legitimacy or contact support if issues arise.

Concerns:
- Extremely poor user rating (1.0 stars) suggests significant functionality or security issues
- Missing developer information creates accountability gaps
- The CSP allows connections to external domains (api.shipengine.com and trackyourorders.net), which could potentially be used for data collection or tracking
- The 'unsafe-inline' directive in the CSP weakens security protections against certain types of attacks
- Storage permission combined with external connections could enable data harvesting
- Low user adoption despite the common need for package tracking suggests the extension may not work as advertised
Recommendations:

Consider running this extension in a separate Chrome profile to isolate potential risks from your main browsing data. Given the poor rating and lack of developer transparency, you might want to explore well-established alternatives with better ratings and clear developer information. If you must use this extension, monitor your stored data and be cautious about what tracking information you input, as it may be transmitted to external servers.

Findings

MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.