CRX aminer
Extension icon

tiny

Version 1.4.2 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Rating: 4.3 ★

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a decent rating of 4.3, which suggests some user satisfaction. However, critical information is missing including the number of users, developer details, and last update date, making it difficult to assess the extension's legitimacy and maintenance status. The minimal name "tiny" and lack of clear description raise additional concerns about transparency.

Concerns:

The extension requests an excessive combination of permissions that create significant security risks. The tabs permission combined with broad content script injection across all URLs creates a dangerous attack surface. The extension can monitor all browsing activity, manipulate any website, and potentially harvest sensitive data including login credentials and personal information. The storage permission allows it to persist collected data locally. The alarms, scripting, and windows permissions further expand its capabilities to perform automated actions and control the browser environment.

Recommendations:

Given the high-risk permission set and lack of transparency, avoid installing this extension unless absolutely necessary. If you must use it, create a dedicated Chrome profile with minimal sensitive browsing activity. Regularly monitor the extension's behavior and remove it immediately if you notice suspicious activity. Consider finding alternative extensions with more limited permissions that accomplish the same functionality. Always verify the developer's identity and read recent reviews before installation.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.