CRX aminer

Starting analysis...

Extension icon

IPL watch party with video chat

Version 1.3.9 View in Chrome Web Store

Last scanned: 27 days ago | force re-scan

Extension Details

Developer: iplparty.com
Rating: 5.0 ★ (2 ratings)
Size: 12.85MiB
Last Updated: April 3, 2024
Users: 127

Context-Aware Verdict

HIGH
Risk Level
Trust Factors:
- The extension has a relatively small user base (127 users), which could indicate a lack of widespread trust or popularity.
- The developer information is limited, making it difficult to assess their reputation or track record.
Concerns:
- The extension requests broad host permissions (*://*/*), allowing it to access all websites, which is unnecessary for its stated purpose of enabling video chat during IPL matches.
- The extension can inject content scripts into any website (<all_urls>), which is a significant privacy and security risk, as it could potentially read sensitive data, modify website content, or steal credentials.
- The "tabs" permission allows the extension to access and manipulate browser tabs, which could be misused for malicious purposes.
- The "storage" and "notifications" permissions are not inherently concerning but should be scrutinized in the context of the extension's functionality.
Recommendations:
- Exercise caution when installing this extension, as it requests excessive permissions that are not aligned with its stated purpose.
- Consider running the extension in a separate browser profile or a sandboxed environment to mitigate potential risks.
- Closely monitor the extension's behavior and uninstall it if any suspicious activity is detected.
- Seek alternative extensions from reputable developers that offer similar functionality with more reasonable permission requests.
- Report the extension to the Chrome Web Store if any malicious behavior is confirmed, to protect other users.

Security Analysis

HIGH
Overall Risk
Based on 5 total findings, ranked without considering overall context, including 3 high-risk and 2 medium-risk findings.
HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.