CRX aminer
Extension icon

Gopeed

Version 1.1.4 View in Chrome Web Store

Last scanned: about 8 hours ago

Extension Details

Developer: gopeed.com
Rating: 4.0 ★ (33 ratings)
Users: 20,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a moderate user base of 20,000 users with a decent 4.0 rating from 33 reviews. However, the developer information is minimal, with only "gopeed.com" listed as the author and no additional developer details provided. The lack of comprehensive developer information reduces trust, especially given the extensive permissions requested.

Concerns:

The extension exhibits several red flags that justify the critical risk rating. The combination of broad host permissions across all websites, content script injection capabilities on all URLs, and powerful API access creates a dangerous permission profile. The webRequest permission allows complete interception and modification of web traffic, while the downloads permission provides access to file downloads and history. The nativeMessaging permission is particularly concerning as it enables communication with native applications outside the browser sandbox. These permissions collectively grant the extension unprecedented access to user data, browsing activity, and system resources.

Recommendations:

Given the critical risk level, avoid installing this extension unless absolutely necessary. If you must use it, run it in a completely isolated Chrome profile with no access to personal accounts or sensitive data. Regularly monitor your download history and network activity for suspicious behavior. Consider using network monitoring tools to track any unusual traffic patterns. Before installation, research the developer more thoroughly and verify the extension's legitimacy through official channels. Alternative download managers with more limited permissions should be strongly considered.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.