CRX aminer
Extension icon

Salesforce Inspector Reloaded BETA

Version 2.0.4 View in Chrome Web Store

Last scanned: about 14 hours ago

Extension Details

Rating: 5.0 ★ (6 ratings)
Users: 2,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension targets Salesforce platforms specifically, which suggests legitimate business use. However, the "BETA" designation raises concerns about stability and testing completeness. With only 2,000 users and 6 ratings, the extension has limited community validation. The perfect 5.0 rating is positive but based on very few reviews. The lack of clear developer information reduces transparency and accountability.

Concerns:

The cookies permission combined with broad Salesforce host access creates significant risk for credential theft or session hijacking across multiple Salesforce domains. The extension can access sensitive business data across numerous Salesforce environments including military (.mil) and international (.cn) domains. The storage permission allows persistent data collection. The BETA status suggests the extension may contain bugs or incomplete security measures. The extensive host permissions cover virtually all Salesforce-related domains, which is unusually broad even for a Salesforce tool.

Recommendations:

Run this extension in a dedicated Chrome profile isolated from other browsing activities. Only install if you specifically need Salesforce inspection capabilities and understand the risks. Monitor your Salesforce sessions for unusual activity. Consider waiting for a stable release rather than using the BETA version. Verify the extension's legitimacy through Salesforce community forums before installation. Regularly review what data the extension has stored locally.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.