CRX aminer
Extension icon

Opportunity Cost

Version 0.0.6 View in Chrome Web Store

Last scanned: about 11 hours ago

Extension Details

Developer: https://opportunitycost.app/
Rating: 4.9 ★ (28 ratings)
Users: 2,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a decent user base of 2,000 users and maintains a strong 4.9-star rating from 28 reviews, suggesting positive user experiences. The developer provides a dedicated website (opportunitycost.app) which adds some legitimacy. However, the extension is still in early development (version 0.0.6) and lacks detailed developer information.
Concerns: The extension's broad permissions are disproportionate to what appears to be a financial calculation tool. The ability to inject content scripts into all websites creates significant security risks, as it could potentially access sensitive financial data, login credentials, or personal information across all browsing sessions. The tabs permission allows monitoring of browsing behavior, which could be used to track spending habits beyond the extension's stated purpose. The combination of these permissions with the early version number raises questions about whether such extensive access is necessary for the core functionality.
Recommendations: Consider running this extension in a separate Chrome profile dedicated to financial planning activities only. Regularly review the extension's behavior and updates given its early development stage. Monitor your browsing data and financial accounts for any unusual activity. If the extension's core functionality doesn't require access to sensitive websites like banking or shopping platforms, consider disabling it when visiting such sites. Given the high-risk permissions, evaluate whether alternative opportunity cost calculators with more limited permissions might serve your needs better.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.