CRX aminer
Extension icon

Global Privacy Control (GPC) Inspector

Version 0.1.4 View in Chrome Web Store

Last scanned: about 9 hours ago

Extension Details

Developer: protegis.io
Rating: 4.4 ★ (9 ratings)
Users: 6,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a moderate user base of 6,000 users with a good rating of 4.4/5, though based on only 9 reviews which limits confidence. The developer protegis.io appears to be focused on privacy tools, which aligns with the extension's stated purpose of inspecting Global Privacy Control signals. However, the limited review count and relatively new status (version 0.1.4) suggest this is still an emerging tool.
Concerns: The extension requests extremely broad permissions that seem excessive for a GPC inspection tool. The webRequest permission allows intercepting and modifying all web traffic, while tabs permission enables monitoring all browser activity. The <all_urls> host permission grants access to every website you visit. For a tool that should primarily inspect GPC headers, these permissions appear unnecessarily invasive and create significant privacy risks. The declarativeNetRequest permissions could also be used to block or modify network requests in ways beyond the stated functionality.
Recommendations: Given the high-risk permission set, consider running this extension in a separate Chrome profile dedicated to privacy testing if you need its functionality. Monitor the extension's network activity using browser developer tools to ensure it's only performing GPC inspection. Consider alternative GPC testing tools with more limited permissions, or use browser developer tools manually to inspect GPC headers. Regularly review what data the extension might be storing locally through the storage permission.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.