CRX aminer
Extension icon

ZAP by Checkmarx Browser Extension

Version 0.0.11 View in Chrome Web Store

Last scanned: 12 days ago | force re-scan

Extension Details

Developer: zaproxy.org
Rating: 4.6 ★
Size: 502KiB
Last Updated: January 21, 2025
Users: 19

Context-Aware Verdict

HIGH
Risk Level
Trust Factors:
- The extension is developed by zaproxy.org, which is a reputable organization in the cybersecurity community, known for their open-source web application security scanner.
- The extension has a relatively high rating of 4.6 stars, indicating positive user feedback.
- However, the extension has a relatively low number of users (19), which could be a concern.
Concerns:
- The extension requests broad host permissions (http://*/*, https://*/*), allowing it to access all websites. This is a significant privacy and security risk, as it could potentially be used to track browsing activity or steal sensitive data.
- The extension has the "tabs" permission, which allows it to access and manipulate browser tabs. This could potentially be misused to compromise security or privacy.
- The extension has the "cookies" permission, which allows it to access and modify browser cookies. This could potentially be used to compromise user accounts or steal sensitive information.
- The extension has the "storage" permission, which allows it to store data locally. While this is a medium-risk permission, it could potentially be used to store sensitive information insecurely.
Recommendations:
- Given the high-risk permissions and broad host permissions, it is recommended to exercise caution when using this extension.
- If you decide to use this extension, consider running it in a separate browser profile or a dedicated browser instance to isolate it from your main browsing activity.
- Regularly review the extension's permissions and update it only from trusted sources to mitigate potential security risks.
- Monitor the extension's behavior and uninstall it if you notice any suspicious activity or performance issues.
- Consider using alternative security tools or extensions from well-known and trusted sources, if available.

Security Analysis

HIGH
Overall Risk
Based on 4 total findings, ranked without considering overall context, including 3 high-risk and 1 medium-risk findings.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.