CRX aminer
Extension icon

AllDebrid Extension

Version 12.0.1 View in Chrome Web Store

Last scanned: about 8 hours ago

Extension Details

Developer: https://alldebrid.fr/
Rating: 4.0 ★ (169 ratings)
Users: 50,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: The extension comes from AllDebrid, a legitimate premium debrid service with 50,000 users and a 4.0 rating. The company has an established reputation in the file hosting/downloading space, which adds some credibility. However, the technical implementation raises significant security concerns that overshadow these positive trust indicators.
Concerns: The extension requests an extremely broad set of permissions that far exceed what's typically necessary for a debrid service. The combination of universal host permissions (*://*/*) with webRequest, webNavigation, tabs, and downloads permissions creates a powerful surveillance and data interception capability. The extension can monitor all web traffic, track browsing across all sites, manipulate downloads, and access sensitive tab information. The nativeMessaging permission suggests communication with external applications, adding another attack vector. These permissions collectively enable comprehensive user monitoring and potential data exfiltration.
Recommendations: Given the critical risk level, install this extension only in a completely separate Chrome profile isolated from personal browsing and sensitive accounts. Never use the same profile for banking, email, or other confidential activities. Consider whether the debrid functionality is worth the extensive privacy trade-offs. Monitor network traffic when the extension is active and regularly review what data might be accessible. Alternative debrid solutions with more limited permissions should be evaluated. If you must use this extension, disable it when not actively needed and consider using it only on a dedicated machine for downloading activities.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.