CRX aminer

Starting analysis...

Extension icon

Export cookie JSON file for Puppeteer

Version 0.3.0 View in Chrome Web Store

Last scanned: 2 days ago | force re-scan

Extension Details

Rating: 4.7 ★ (13 ratings)
Users: 10,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a decent user base of 10,000 users and maintains a strong 4.7-star rating from 13 reviews, suggesting users find it functional. However, the lack of visible author information and developer details raises transparency concerns. The extension appears to serve a legitimate technical purpose for developers working with Puppeteer automation.
Concerns: The extension requests extremely broad permissions that extend far beyond what's necessary for cookie export functionality. The combination of tabs permission, cookies access, and universal host permissions (http://*/*, https://*/*) creates a powerful surveillance capability. While cookie access is expected for this tool, the tabs permission seems unnecessary for simply exporting cookie data. The broad host permissions allow the extension to access cookies from every website you visit, not just when you actively choose to export them.

The security findings correctly identify these as high-risk permissions that could enable malicious activities like session hijacking, cross-site tracking, or data theft across all browsing sessions.

Recommendations: Consider running this extension in a separate Chrome profile dedicated to development work only. Before installation, verify you actually need this functionality - many developers can export cookies through browser developer tools instead. If you must use it, regularly audit your installed extensions and remove it when not actively needed. Monitor for any unusual network activity or unexpected behavior while the extension is active.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.