CRX aminer
Extension icon

Fingerprint Spoofer

Version 1.0.0 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Rating: 5.0 ★ (1 rating)
Users: 312

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: This extension has several concerning trust indicators. With only 312 users and a single 5-star rating, it lacks the user base and review history that would indicate reliability. The absence of clear developer information makes it difficult to verify the creator's legitimacy or track record. The extension's purpose of "fingerprint spoofing" inherently involves deceptive practices that could be used for both legitimate privacy protection and malicious activities.
Concerns:
- Extremely broad permissions that far exceed what's necessary for basic fingerprint spoofing functionality
- Access to all websites through both host permissions and content script injection creates massive attack surface
- Specific targeting of Google's reCAPTCHA systems suggests potential for bypassing security measures
- The combination of storage permissions with broad web access enables comprehensive data collection and tracking
- Lack of transparency about the developer's identity and intentions
- Low user adoption may indicate the extension hasn't been thoroughly vetted by the community
Recommendations:

Run this extension in a completely separate Chrome profile isolated from your main browsing activities. Consider using established, well-reviewed privacy tools instead. If you must use this extension, monitor your network traffic and regularly audit what data it might be collecting. Be particularly cautious when visiting sensitive sites like banking or email services while this extension is active. The broad permissions combined with the suspicious targeting of security systems make this extension unsuitable for general use.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: *://*.google.com/recaptcha/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.