CRX aminer
Extension icon

SFX Sourcing Assistant

Version 1.1.0 View in Chrome Web Store

Last scanned: about 1 hour ago

Extension Details

Rating: 5.0 ★ (1 rating)
Users: 71

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: This extension has very limited trust indicators with only 71 users and a single 5-star rating, making it difficult to assess reliability. The lack of developer information and company details raises transparency concerns. The extension appears to be a specialized tool for sourcing/recruiting workflows given its focus on LinkedIn, Indeed, and SmashFly platforms.
Concerns:
- The tabs permission is excessive for a sourcing assistant and allows broad access to all browser tabs and their information
- Cookie access permission could enable session hijacking or unauthorized account access across the supported platforms
- Manifest V2 usage indicates outdated security standards
- Very small user base provides insufficient community validation
- Missing developer contact information reduces accountability
- The combination of tabs and cookies permissions creates significant privacy and security exposure
- Access to recruiting platforms could potentially compromise sensitive candidate data
Recommendations:

Consider running this extension in a separate Chrome profile dedicated to recruiting activities to limit exposure. Before installation, verify the extension's legitimacy through the developer's official channels. Monitor for any unusual browser behavior or unauthorized access to accounts. Given the high-risk permissions and limited trust factors, consider alternative sourcing tools with better security practices and larger user bases. If you must use this extension, regularly review your LinkedIn and Indeed account activity for suspicious access.

Findings

HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.