CRX aminer
Extension icon

pCloud Save

Version 2.0.2 View in Chrome Web Store

Last scanned: about 12 hours ago

Extension Details

Rating: 3.0 ★ (141 ratings)
Users: 20,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension is developed by pCloud, a legitimate cloud storage company with an established reputation. However, the moderate user base of 20,000 users and concerning 3.0 rating from 141 reviews suggest potential issues with functionality or user experience. The lack of recent update information raises questions about ongoing maintenance and security patches.

Concerns:

The extension requests excessive permissions that appear unnecessary for basic cloud saving functionality. The combination of tabs permission with broad host permissions (<all_urls>) creates significant privacy risks, allowing the extension to monitor and access all browsing activity across every website. The ability to inject content scripts into all websites is particularly concerning, as this could enable data harvesting, credential theft, or website manipulation. The declarativeNetRequest permission adds another layer of network-level access that seems disproportionate for a file saving tool.

Recommendations:

Consider running this extension in a separate Chrome profile to isolate it from your primary browsing activities and sensitive accounts. Before installation, verify that you actually need the advanced features that might justify these broad permissions. Monitor the extension's behavior closely after installation, particularly any unexpected network requests or changes to website functionality. Consider alternative cloud storage extensions with more limited permission sets if you only need basic file saving capabilities. Regularly review and audit the extension's permissions through Chrome's extension management interface.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://www.google-analytics.com/. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.