CRX aminer
Extension icon

Wordvice AI Writing Assistant: Grammar Checker, Translator, Paraphraser

Version 1.0.4 View in Chrome Web Store

Last scanned: 2 days ago | force re-scan

Extension Details

Developer: wordvice.ai
Rating: 4.6 ★ (9 ratings)
Users: 10,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension comes from wordvice.ai, which appears to be a legitimate writing assistance service. With 10,000 users and a 4.6-star rating from 9 reviews, it shows some positive user feedback, though the review count is relatively low for the user base. The extension's purpose as a grammar checker, translator, and paraphraser aligns with its requested permissions for text processing across websites.

Concerns:

The extension exhibits several concerning security characteristics that justify the critical risk rating. The combination of broad host permissions with all_urls access and content script injection capabilities creates significant privacy and security exposure. The cookies permission is particularly concerning for a writing tool, as it could potentially access authentication tokens and session data. The tabs permission allows monitoring of browsing activity beyond what's necessary for text assistance. The extension can essentially read and modify content on any website you visit, including sensitive financial, medical, or personal sites.

Recommendations:

Given the critical risk level, consider running this extension in a completely separate Chrome profile dedicated only to writing tasks. Alternatively, look for writing assistance tools that work as standalone applications or browser-based services without requiring such extensive permissions. If you must use this extension, disable it when not actively writing and avoid using it while accessing sensitive websites like banking or healthcare portals. Monitor your accounts for any unusual activity after installation.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://docs.google.com/*, https://sheets.google.com/*, https://slides.google.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.