CRX aminer

Starting analysis...

Extension icon

Wordcounter

Version 1.3 View in Chrome Web Store

Last scanned: about 2 months ago | force re-scan

Extension Details

Rating: 2.6 ★ (38 ratings)
Users: 1,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors: The extension has concerning trust indicators with only 1,000 users and a low rating of 2.6 out of 5 stars from 38 reviews, suggesting user dissatisfaction. The lack of developer information and missing last updated date raises transparency concerns. For a simple word counting tool, these metrics indicate limited adoption and potential quality issues.
Concerns:
- Low user rating (2.6/5) suggests functionality or reliability problems
- Missing developer information reduces accountability and trustworthiness
- Uses outdated Manifest V2 with weaker security protections
- Content script injection specifically targets Google Docs, which could access sensitive documents
- Storage permission allows data retention, potentially including document content
- ActiveTab permission provides access to current webpage content when activated

The combination of activeTab and storage permissions is concerning for a word counter, as it could theoretically collect and store text from documents you're working on. The specific targeting of Google Docs through content scripts adds risk when working with confidential documents.

Recommendations: Consider using a more established word counting extension with better ratings and transparency. If you must use this extension, run it in a separate Chrome profile when working with sensitive documents. Monitor what data might be stored locally and consider alternatives that don't require content script injection into document platforms.

Findings

MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.