CRX aminer
Extension icon

Wordvice AI Writing Assistant: Grammar Checker, Translator, Paraphraser

Version 1.0.4 View in Chrome Web Store

Last scanned: about 12 hours ago

Extension Details

Developer: wordvice.ai
Rating: 5.0 ★ (7 ratings)
Users: 10,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension comes from wordvice.ai, which appears to be a legitimate writing assistance service. However, several concerning factors diminish trust: only 10,000 users despite being a writing tool, extremely limited rating data (only 7 reviews), and missing key details like developer information and last update date. The perfect 5.0 rating with so few reviews is suspicious and could indicate review manipulation.

Concerns:

The extension requests extremely broad permissions that far exceed what's necessary for a grammar checker and writing assistant. The <all_urls> host permission combined with content script injection capabilities means it can access and modify content on every website you visit. The cookies permission allows it to access your login sessions and authentication data across all sites. The tabs permission enables monitoring of your browsing activity. These permissions would allow the extension to steal sensitive information, track your online behavior, and potentially compromise your accounts.

Recommendations:

Do not install this extension in your main browser profile. If you must use it, create a completely separate Chrome profile with no saved passwords or sensitive browsing data. Consider using established alternatives like Grammarly that have better security track records. The risk-to-benefit ratio is extremely poor given the extensive permissions requested for basic writing assistance functionality. The broad access capabilities make this extension a significant security liability.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://docs.google.com/*, https://sheets.google.com/*, https://slides.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.