CRX aminer
Extension icon

Enable Copy Everywhere

Version 1.1.0 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Rating: 4.2 ★ (27 ratings)
Users: 60,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a moderate user base of 60,000 users and a decent rating of 4.2/5, suggesting some level of user satisfaction. However, the lack of developer information and company details raises transparency concerns. The extension's purpose - enabling copy functionality on websites that normally restrict it - is legitimate and addresses a common user need.

Concerns:

The extension's permission set is extremely broad and excessive for its stated functionality. The combination of tabs permission, universal host permissions (*://*/*), and content script injection across all URLs creates a powerful surveillance and data collection capability. The gcm (Google Cloud Messaging) permission is particularly concerning as it enables remote communication that could be used for data exfiltration. For a simple copy-enabling tool, these permissions represent significant overreach that could allow the extension to monitor all browsing activity, access sensitive data on any website, and potentially steal credentials or personal information.

Recommendations:

Given the high risk profile, consider running this extension in a separate Chrome profile isolated from sensitive browsing activities. Before installation, evaluate if the copy functionality is truly necessary for your workflow. Alternative solutions include using browser developer tools to temporarily disable copy restrictions, or seeking extensions with more limited permissions that achieve the same goal. If you must use this extension, regularly audit your browsing data and consider using it only on non-sensitive websites.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.