CRX aminer
Extension icon

TextExpander: Keyboard Shortcuts & Templates

Version 843.1 View in Chrome Web Store

Last scanned: about 1 hour ago

Extension Details

Developer: TextExpander, Inc.
Rating: 4.5 ★ (143 ratings)
Users: 100,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: TextExpander is a well-established productivity company with a legitimate business model focused on text expansion and automation. The extension has 100,000 users and a solid 4.5-star rating from 143 reviews, indicating general user satisfaction. The company has been in the text expansion market for years and has a reputation for providing useful productivity tools.
Concerns: While the extension's core functionality justifies many permissions, several raise significant privacy concerns. The combination of clipboard read/write access with broad host permissions creates potential for sensitive data exposure. The extension can access all websites and inject scripts universally, which exceeds what's typically needed for text expansion. The unsafe WebAssembly execution permission is particularly concerning as it could hide malicious code. Native messaging capability suggests communication with external applications, expanding the attack surface.

The broad content script injection across all URLs means this extension can potentially read everything you type, including passwords, personal information, and sensitive documents on any website you visit.

Recommendations: Given the legitimate use case but extensive permissions, consider running this extension in a dedicated Chrome profile for work-related activities only. Avoid using it while accessing sensitive sites like banking or personal accounts. Regularly review what data the extension has access to and consider whether the productivity benefits outweigh the privacy trade-offs. Monitor for any unusual behavior or unexpected clipboard modifications.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: clipboardRead
This extension has the clipboardRead permission. Can read clipboard content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: clipboardWrite
This extension has the clipboardWrite permission. Can modify clipboard content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.