CRX aminer
Extension icon

Vonage® Integration Suite

Version 2025.917.1612.1 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Rating: 2.2 ★ (19 ratings)
Users: 30,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension is published by Vonage, a legitimate telecommunications company, which provides some credibility. However, the trust is significantly undermined by the extremely low rating of 2.2 out of 5 stars from only 19 reviews, suggesting poor user experience or functionality issues. With 30,000 users, it has moderate adoption but the negative feedback is concerning.

Concerns:

The extension requests extensive permissions that appear excessive for a business communication tool. The tabs permission combined with broad host permissions creates significant privacy risks, allowing access to sensitive information across multiple platforms including Salesforce, Google services, LinkedIn, and Microsoft Dynamics. The content scripts run on all HTTP/HTTPS sites, creating potential for data interception. The contextMenus permission adds another attack vector for malicious activity.

The scope of accessible domains is unusually broad for an integration suite, including development and staging environments that could expose internal systems. The combination of storage permissions with broad site access creates opportunities for data harvesting.

Recommendations:

Given the high risk level, install this extension only in a separate Chrome profile dedicated to Vonage-related work. Regularly audit what data the extension accesses and consider whether all the integrated platforms are necessary for your use case. Monitor for any suspicious network activity and consider alternative solutions with more limited permissions if available.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.