CRX aminer

Starting analysis...

Extension icon

Nexthink

Version 26.1.4 View in Chrome Web Store

Last scanned: 21 days ago | force re-scan

Extension Details

Rating: 4.0 ★ (26 ratings)
Users: 7,000,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a substantial user base of 7 million users, which suggests widespread enterprise adoption. However, the rating of 4.0 with only 26 reviews is concerning given the large user count, indicating limited user engagement or feedback. Nexthink is a legitimate digital employee experience company that provides workplace analytics, which explains the extensive permissions required for monitoring and data collection purposes.

Concerns:

The extension requests extremely broad permissions that essentially grant complete browser access. The combination of webRequest interception, downloads access, identity permissions, and universal host permissions creates a powerful surveillance capability. The nativeMessaging permission allows communication with local applications, potentially expanding the attack surface beyond the browser. The scripting permission combined with <all_urls> access means this extension can execute code on any website you visit. For a workplace monitoring tool, these permissions may be necessary but represent significant privacy implications.

Recommendations:

This appears to be an enterprise monitoring solution deployed by employers. If you're using a work computer, this extension is likely required by your organization's IT policy. For personal use, avoid installing this extension as it provides comprehensive tracking capabilities. If you must use it, consider running it in a dedicated Chrome profile separate from personal browsing. Be aware that this extension can monitor virtually all browser activity, including downloads, web navigation, and potentially sensitive information across all websites.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.