CRX aminer
Extension icon

BBCRM Sherpa

Version 1.2.0 View in Chrome Web Store

Last scanned: about 9 hours ago

Extension Details

Rating: 5.0 ★ (1 rating)
Users: 18

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors: The extension has very limited adoption with only 18 users and a single 5-star rating, which provides insufficient data to establish trustworthiness. The lack of developer information, company details, and update history raises transparency concerns. The name "BBCRM Sherpa" suggests it's related to CRM functionality, but without a clear description, its actual purpose remains unclear.
Concerns: The history permission is particularly concerning given the extension's unclear purpose and minimal user base. Access to browsing history is a sensitive permission that could expose personal browsing patterns, visited websites, and potentially confidential information. The storage permission, while less critical, allows data persistence which could be used to collect and retain user information. The combination of these permissions with the lack of transparency about the developer and extension functionality creates potential privacy risks.
Recommendations: Given the medium risk level and unclear legitimacy, consider running this extension in a separate Chrome profile to isolate potential risks from your main browsing environment. Before installation, try to verify the extension's actual purpose and developer credentials. Monitor the extension's behavior closely and consider whether the CRM functionality it presumably provides is worth the privacy trade-offs. If possible, look for alternative CRM extensions from more established developers with better transparency and user adoption rates.

Findings

HIGH
High-Risk Permission: history
This extension has the history permission. Can access your browsing history. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.