CRX aminer

Starting analysis...

Extension icon

Tripadvisor: Travel Advice & Deals on Hotels, Restaurants & Attractions

Version 1.3.0.8 View in Chrome Web Store

Last scanned: 14 days ago | force re-scan

Extension Details

Developer: tripadvisor.com
Rating: 4.6 ★ (107 ratings)
Size: 2.16MiB
Last Updated: April 25, 2025
Users: 70,000

Context-Aware Verdict

HIGH
Risk Level
Trust Factors:
- The extension is published by Tripadvisor, a well-known travel company, which adds some credibility.
- It has a relatively high number of users (70,000) and a good rating (4.6/5), suggesting many users find it useful.
Concerns:
- The extension requests several high-risk permissions (webNavigation, webRequest) that could potentially be abused to track browsing activity or compromise security/privacy.
- It has very broad host permissions to access all websites, which is unnecessary for a travel extension.
- It can inject scripts into any website, raising privacy and security risks.
Recommendations:
- Consider running this extension in a separate browser profile or incognito window to isolate it from other browsing activity.
- Review the extension's data practices and make sure you are comfortable with how it handles user data.
- Monitor for any suspicious behavior, such as unexpected network activity or website modifications.
- Use caution when entering sensitive information on websites while this extension is running.
- Consider using alternative travel extensions with more limited permissions if they meet your needs.

Overall, while the extension is from a reputable company, its very broad permissions and ability to inject scripts into any website raise significant privacy and security concerns. Careful monitoring and containment strategies are recommended if you choose to use this extension.

Security Analysis

CRITICAL
Overall Risk
Based on 6 total findings, ranked without considering overall context, including 4 high-risk and 2 medium-risk findings.
HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.