CRX aminer
Extension icon

Shop Blue Assistant

Version 4.0.1 View in Chrome Web Store

Last scanned: about 13 hours ago

Extension Details

Rating: 2.5 ★ (22 ratings)
Users: 10,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has several concerning trust indicators. With only 10,000 users and a poor 2.5-star rating from just 22 reviews, it shows limited adoption and user satisfaction. The lack of developer information and company details raises transparency concerns. The generic name "Shop Blue Assistant" provides little clarity about its actual purpose or functionality.

Concerns:

The extension requests an excessive combination of high-risk permissions that far exceed what a typical shopping assistant would need. The ability to access all websites, intercept web requests, and manipulate cookies creates significant privacy and security vulnerabilities. The broad content script injection capability means it can read sensitive information like passwords, credit card details, and personal data from any website you visit. The webRequest permission allows it to potentially redirect traffic or inject malicious content into legitimate websites.

Recommendations:

Do not install this extension due to its critical risk level. If you must use it for essential business purposes, create a completely separate Chrome profile with no saved passwords, payment information, or access to sensitive websites. Consider using alternative shopping assistants from reputable developers with better ratings and more transparent permission models. The combination of broad permissions, poor ratings, and lack of developer transparency suggests this extension poses significant security risks that outweigh any potential benefits.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.