CRX aminer
Extension icon

Shopee Fans - Shopee Seller Assistant

Version 8.7.5 View in Chrome Web Store

Last scanned: about 9 hours ago

Extension Details

Developer: shopeefans.com
Rating: 4.6 ★ (122 ratings)
Users: 30,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a decent user base of 30,000 users and a good rating of 4.6 stars from 122 reviews, which suggests legitimate functionality. The developer domain shopeefans.com appears to be focused on Shopee seller tools, which aligns with the extension's stated purpose as a seller assistant.

Concerns:

The extension presents significant security risks due to its extremely broad permissions and access scope. The all_urls host permission combined with access to dozens of major e-commerce platforms (Shopee, Amazon, AliExpress, Lazada, TikTok Shop, etc.) creates a massive attack surface. The downloads permission allows file downloads which could be exploited for malware distribution. Cookie access across all these platforms could enable session hijacking or account compromise. The webNavigation permission enables comprehensive browsing tracking across all visited sites. The combination of these permissions with such broad host access creates potential for data theft, financial fraud, or comprehensive user surveillance.

Recommendations:

Given the critical risk level, install this extension only in a completely separate Chrome profile isolated from personal browsing and sensitive accounts. Never use the same profile for banking, personal email, or other sensitive activities. Consider whether the seller assistant functionality truly requires such extensive permissions - many legitimate tools operate with much more limited access. Monitor your accounts closely for any suspicious activity if you choose to use this extension. Consider alternative Shopee seller tools with more restricted permissions.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.