CRX aminer

Starting analysis...

Extension icon

CORS Unblock

Version 0.3.8 View in Chrome Web Store

Last scanned: 13 days ago | force re-scan

Extension Details

Rating: 4.2 ★ (167 ratings)
Size: 203KiB
Last Updated: February 11, 2024
Users: 200,000

Context-Aware Verdict

HIGH
Risk Level
Trust Factors:
- The extension has a relatively high number of users (200,000), which could indicate some level of trust and popularity.
- However, the lack of developer information or a reputable company behind the extension raises some concerns about transparency and accountability.
Concerns:
- The extension requests a concerning combination of permissions, including the ability to access all websites and their content (<all_urls>), intercept and modify web requests (webRequest, webRequestBlocking), and debug other extensions/apps (debugger).
- These permissions could potentially be abused to compromise user security and privacy, such as by modifying sensitive web traffic or stealing data.
- The use of an older manifest version (Manifest V2) also raises some security concerns, as it has fewer restrictions than the newer Manifest V3.
Recommendations:
- Exercise caution when using this extension, as it has a high risk level and could potentially compromise your security and privacy.
- If you must use this extension, consider running it in a separate Chrome profile or a sandboxed environment to isolate it from your main browsing activities.
- Look for alternative extensions that achieve similar functionality but with fewer permissions or from more reputable developers.
- Keep the extension updated to the latest version and monitor for any suspicious behavior or privacy concerns.
- Consider using additional security measures, such as a reputable antivirus software or a virtual private network (VPN), to enhance your overall online security.

Security Analysis

CRITICAL
Overall Risk
Based on 8 total findings, ranked without considering overall context, including 5 high-risk and 3 medium-risk findings.
HIGH
Dangerous Permission Combination: webRequest + webRequestBlocking
This extension can intercept, modify, and block web requests in real-time. This combination could be used to modify sensitive web traffic or steal data.
HIGH
High-Risk Permission: <all_urls>
This extension has the <all_urls> permission. Can access all websites and their content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: debugger
This extension has the debugger permission. Can debug and manipulate other extensions/apps. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequestBlocking
This extension has the webRequestBlocking permission. Can block and modify web requests in real-time. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.