CRX aminer
Extension icon

UpNote Web Clipper

Version 1.2.2 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Rating: 3.1 ★ (104 ratings)
Users: 30,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a moderate user base of 30,000 users, which suggests some level of community adoption. However, the relatively low rating of 3.1 out of 5 from 104 reviews raises concerns about user satisfaction and potentially problematic functionality. The lack of clear developer information makes it difficult to assess the company's reputation and trustworthiness.

Concerns:

The primary security concern is the broad content script injection capability that allows the extension to run scripts on all websites (*://*/*). While this functionality may be necessary for a web clipper to capture content from any webpage, it creates significant security risks. The extension could potentially access sensitive information like passwords, personal data, or financial information on banking sites. The combination of broad permissions with a below-average user rating suggests possible issues with the extension's implementation or behavior.

Recommendations:

Given the medium risk level, consider running this extension in a separate Chrome profile dedicated to web clipping activities. Avoid using it while accessing sensitive websites like banking, email, or other accounts containing personal information. Monitor the extension's behavior closely and consider alternative web clipping tools with better security practices and higher user ratings. If you must use this extension, regularly review what data it has access to and consider disabling it when not actively clipping content.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.