CRX aminer

Starting analysis...

Extension icon

Keybase

Version 1.10.16 View in Chrome Web Store

Last scanned: about 1 month ago | force re-scan

Extension Details

Developer: keybase.io
Rating: 4.0 ★ (65 ratings)
Size: 434KiB
Last Updated: October 8, 2018
Users: 5,000

Context-Aware Verdict

MEDIUM
Risk Level
Trust Factors:
- The extension is developed by Keybase, a reputable company focused on secure messaging and file sharing.
- It has a decent number of users (5,000) and a relatively high rating (4.0/5) from 65 reviews, suggesting a level of trust from the user community.
Concerns:
- The extension requests several permissions that may be considered unnecessary or overly broad for its stated purpose, such as activeTab, contextMenus, and declarativeContent.
- The content scripts have access to various popular websites like Reddit, Twitter, Facebook, GitHub, and Hacker News, which could potentially be a privacy concern if the extension is not handling user data securely.
- The extension is still using the older Manifest Version 2, which has fewer security restrictions compared to the newer Manifest Version 3.
Recommendations:
- Review the extension's privacy policy and terms of service to understand how user data is handled and what the extension's capabilities are.
- Consider running the extension in a separate Chrome profile or a dedicated browser instance to isolate it from your main browsing activities.
- Monitor the extension's behavior and network activity for any suspicious or unexpected actions.
- Keep an eye on updates from the developer and the extension's reviews to stay informed about any potential issues or concerns raised by the community.
- If you have concerns about the extension's permissions or behavior, consider uninstalling it or using an alternative solution that better aligns with your security and privacy requirements.

Security Analysis

MEDIUM
Overall Risk
Based on 4 total findings, ranked without considering overall context, including 0 high-risk and 4 medium-risk findings.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.