CRX aminer
Extension icon

BrickSeek Addon

Version 1.8 View in Chrome Web Store

Last scanned: about 9 hours ago

Extension Details

Rating: 4.0 ★ (4 ratings)
Users: 443

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has very limited adoption with only 443 users and minimal reviews (4 ratings), which provides little community validation. The lack of developer information and company details raises transparency concerns. While the 4.0 rating suggests basic functionality, the small sample size makes this less meaningful. The extension appears to be related to BrickSeek, a legitimate inventory tracking service, but without clear developer attribution, this connection cannot be verified.

Concerns:

The extension requests extremely broad permissions that seem excessive for a BrickSeek-related tool. The <all_urls> permission combined with content script injection across all websites creates significant privacy and security risks. The tabs permission allows manipulation of browser tabs, which could be misused for malicious redirects or data theft. The use of outdated Manifest V2 indicates the extension hasn't been updated to meet modern security standards. The broad access permissions could enable credential harvesting, sensitive data collection, or unauthorized website modifications across all browsing activity.

Recommendations:

Given the high-risk profile, run this extension in a completely separate Chrome profile isolated from your main browsing activities. Consider whether the BrickSeek functionality is essential enough to justify these security risks. Look for alternative extensions with more limited permissions or use BrickSeek's website directly. If you must use this extension, regularly audit your stored passwords and consider using it only when specifically needed for BrickSeek-related activities, then disabling it afterward.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
High-Risk Permission: <all_urls>
This extension has the <all_urls> permission. Can access all websites and their content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.