CRX aminer
Extension icon

Bold Rewards

Version 1.14.0 View in Chrome Web Store

Last scanned: about 12 hours ago

Extension Details

Developer: bold.org
Rating: 4.8 ★ (114 ratings)
Users: 40,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a solid user base of 40,000 users and maintains a high rating of 4.8 stars from 114 reviews, suggesting positive user experiences. The developer bold.org appears to be associated with a legitimate organization focused on educational scholarships and rewards. However, the lack of detailed developer information and missing last updated date raise some transparency concerns.

Concerns:

The extension's permission set is extremely broad and powerful for a rewards program. The combination of webRequest, cookies, tabs, and universal host permissions creates a surveillance-capable tool that can monitor, intercept, and modify all web traffic across every website. The scripting permission allows code injection into web pages, while content scripts are specifically targeting major e-commerce sites (Amazon, Walmart) and AI platforms (ChatGPT, Claude, Perplexity). This suggests the extension may be collecting detailed browsing and shopping data far beyond what's necessary for a typical rewards program.

Recommendations:

Given the critical risk level, consider running this extension in a completely separate Chrome profile isolated from sensitive browsing activities. Before installation, carefully review the privacy policy to understand what data is collected and how it's used. Monitor your browsing behavior and network traffic after installation. Consider whether the rewards offered justify the extensive data access permissions. Alternative reward programs with more limited permissions may provide similar benefits with reduced privacy risks.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.