CRX aminer

Version 1.0.83 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension lacks critical identifying information including name, description, author details, user count, ratings, and last update date. This absence of basic metadata is highly concerning and suggests either an incomplete installation or potentially malicious software attempting to hide its identity. Without download statistics or user reviews, there's no way to verify community trust or developer reputation.
Concerns: The extension requests powerful permissions including tabs access and broad host permissions for WhatsApp Web and external domains. The tabs permission allows manipulation of browser tabs and access to sensitive browsing information. The combination of scripting permissions with WhatsApp Web access suggests this may be designed to automate messaging, which could violate WhatsApp's terms of service. The connection to premiumsender.app and ip-api.com domains raises questions about data collection and potential commercial messaging automation. The unlimitedStorage permission could enable extensive data harvesting.
Recommendations: Do not install or immediately remove this extension due to the missing identification information. If you must use WhatsApp automation tools, research well-established alternatives with clear developer information, user reviews, and transparent privacy policies. Consider using WhatsApp Business API for legitimate business messaging needs. If already installed, run it in an isolated Chrome profile and monitor network activity closely. Report this extension to Chrome Web Store if encountered there.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.