The extension has a strong user rating of 4.9 stars from 722 reviews and serves 20,000 users, indicating positive user experiences. The developer domain matches the extension name (xpet.tech), suggesting legitimate ownership. However, the lack of detailed description raises questions about transparency regarding the extension's actual functionality.
The tabs permission is concerning as it allows broad access to browser tab information and manipulation capabilities, which seems excessive for what appears to be a pet-related application. The content scripts specifically target Twitter/X and the developer's own domain, suggesting social media integration, but the tabs permission could enable monitoring of all browsing activity. The missing description makes it difficult to assess whether these permissions are justified for the extension's stated purpose.
Given the medium risk level, consider running this extension in a separate Chrome profile to isolate potential privacy risks. Before installation, research the extension's actual functionality through user reviews and the developer's website to understand why it needs tabs access. Monitor your browsing behavior after installation for any unusual activity. If the extension's core functionality doesn't clearly require tab manipulation, consider looking for alternatives with more limited permissions. The storage permission alone would be sufficient for most pet-related applications.
| https://github.com/MikeMcl/decimal.js | https://x.com | |
| https://api.simplesvg.com | https://api.unisvg.com | |
| https://api.iconify.design | http://www.w3.org/2000/svg | |
| http://www.w3.org/1999/xlink | https://fonts.googleapis.com/css2?family=Pixelify+Sans&display=swap | |
| https://reactjs.org/docs/error-decoder.html?invariant= | http://www.w3.org/XML/1998/namespace | |
| http://www.w3.org/1998/Math/MathML | http://www.w3.org/1999/xhtml | |
| https://openchain.xyz/signatures?query= | https://viem.sh | |
| https://eth-mainnet.g.alchemy.com/v2 | https://mainnet.infura.io/v3 | |
| https://cloudflare-eth.com | https://etherscan.io | |
| https://eth-goerli.g.alchemy.com/v2 | https://goerli.infura.io/v3 | |
| https://rpc.ankr.com/eth_goerli | https://goerli.etherscan.io | |
| https://ipfs.io | https://arweave.net | |
| https://wagmi.sh/core/providers/jsonRpc | https://wagmi.sh/react/config | |
| https://wagmi.sh/react/WagmiConfig | https://arb-sepolia.g.alchemy.com/v2 | |
| https://sepolia-rollup.arbitrum.io/rpc | https://sepolia.arbiscan.io | |
| https://arb-mainnet.g.alchemy.com/v2 | https://arbitrum-mainnet.infura.io/v3 | |
| https://arb1.arbitrum.io/rpc | https://arbiscan.io | |
| https://arbitrum-one.publicnode.com | https://mui.com/production-error/?code= | |
| https://github.com/pmndrs/jotai/discussions/2044 | https://api-v2.xpet.tech | |
| https://fi.xpet.tech | https://pvp-api-v2.xpet.tech | |
| https://chrome.google.com/webstore/detail/okx-wallet/mcohilncbfahbmgdjkbpemcciiolgcge | https://chromewebstore.google.com/detail/bitget-wallet-tr%C6%B0%E1%BB%9Bc-%C4%91%C3%A2y-l/jiidiaalihmmhddjgbnbgdfflelocpak | |
| https://arbiscan.io/tx/ | https://www.okx.com/vi/web3/marketplace/nft/collection/arbi/xpet-santa-hat | |
| https://bugs.webkit.org/show_bug.cgi?id=68196 | https://x.com/ | |
| https://x.com/xpet_tech | https://x.com/xpet_tech/status/ | |
| https://www.okx.com/vi/web3 | https://x.com/anyuser/status/ | |
| https://web3.bitget.com/ | https://space3.gg/missions/xpet-ancient8 | |
| https://web3.bitget.com/vi/bwb-airdrop | https://twitter.com/ | |
| https://twitter.com/home | https://clients2.google.com/service/update2/crx | |
| https://www.xpet.tech | https://docs.xpet.tech | |
| http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd |
{ "name": "xPet.tech", "icons": { "34": "img/icon-34.png", "128": "img/icon-128.png" }, "action": { "default_icon": "img/icon-34.png", "default_popup": "popup.html" }, "version": "5.4.0", "background": { "service_worker": "background.bundle.js" }, "update_url": "https://clients2.google.com/service/update2/crx", "description": "Raising your virtual pet on X, hunting chest and farming $BPET token", "permissions": [ "tabs", "storage" ], "content_scripts": [ { "js": [ "contentScript.bundle.js" ], "matches": [ "https://twitter.com/*", "https://*.xpet.tech/*", "https://x.com/*" ] } ], "manifest_version": 3, "web_accessible_resources": [ { "matches": [ "<all_urls>" ], "resources": [ "img/*", "*.png", "inpage.bundle.js" ] } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.