CRX aminer

Starting analysis...

Extension icon

ServiceNow Switch Instance

Version 1.0.6 View in Chrome Web Store

Last scanned: 3 days ago | force re-scan

Extension Details

Rating: 5.0 ★ (2 ratings)
Users: 180

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a perfect 5.0 rating, though this is based on only 2 reviews. With just 180 users, it has a very small user base which limits community validation. The lack of developer information and company details raises transparency concerns. The extension appears to be a utility tool for ServiceNow users to switch between instances, which is a legitimate business use case.

Concerns:

The tabs permission is the primary concern as it allows broad access to browser tab information and manipulation capabilities, which extends beyond what would typically be needed for instance switching. The activeTab permission, while more reasonable, still grants access to the current tab's content. The use of Manifest V2 indicates the extension hasn't been updated to meet newer security standards. The very small user base and limited review history make it difficult to assess real-world safety.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to ServiceNow work to limit potential exposure. Before installing, verify that your organization approves this tool and consider whether ServiceNow's native instance switching capabilities meet your needs. Monitor the extension's behavior and remove it if you notice any unexpected tab manipulation. Look for alternative extensions with larger user bases and more transparent developer information, or request your IT department to evaluate official ServiceNow tools for instance management.

Findings

HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.