CRX aminer
Extension icon

Multi-RTL

Version 6.3.1 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Developer: https://multi-rtl.asia-digital.online/
Rating: 5.0 ★ (15 ratings)
Users: 1,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has very limited trust indicators with only 1,000 users and 15 ratings, suggesting minimal adoption. The perfect 5.0 rating could indicate either genuine satisfaction or insufficient review volume. The developer website (multi-rtl.asia-digital.online) appears to be a non-standard domain, which raises questions about the developer's legitimacy and long-term commitment.

Concerns:

The extension exhibits several red flags that justify a critical risk assessment. The combination of identity permissions with broad host access creates a dangerous attack surface - it can access your Google identity information while simultaneously having unrestricted access to all websites you visit. The content script injection capability across all URLs means it could potentially intercept login credentials, banking information, or other sensitive data on any website. The storage permission, while seemingly benign, could be used to persist stolen data. Most concerning is that these extensive permissions appear disproportionate for what seems to be an RTL (right-to-left text) formatting tool, suggesting potential overreach or malicious intent.

Recommendations:

Do not install this extension given the critical risk level. If RTL text support is needed, seek alternatives from established developers with transparent privacy policies and appropriate permission scopes. If you must use this extension, run it in a completely isolated Chrome profile with no access to sensitive accounts or websites, and monitor your accounts closely for any unauthorized activity.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.