CRX aminer
Extension icon

Hospitable - Vrbo Connection

Version 1.2.5 View in Chrome Web Store

Last scanned: about 5 hours ago

Extension Details

Rating: 1.8 ★ (41 ratings)
Users: 10,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: The extension has concerning trust indicators with only 10,000 users and a very low rating of 1.8 out of 5 stars from 41 reviews, suggesting significant user dissatisfaction. The lack of clear developer information and company details raises additional transparency concerns. While the extension appears to serve a legitimate business purpose (connecting Hospitable property management with Vrbo), the poor user feedback indicates potential functionality or reliability issues.
Concerns: The extension requests excessive permissions that seem unnecessary for its stated purpose of connecting Hospitable with Vrbo. The clipboardWrite permission is particularly concerning as it allows modification of clipboard content, which could be exploited to inject malicious data. The cookies permission combined with broad host access creates privacy risks, as it could potentially access sensitive authentication data across multiple domains. The tabs permission allows extensive browser manipulation beyond what would be expected for a simple property management connector.
Recommendations: Given the critical risk level and poor user ratings, avoid installing this extension. If you must use it for business purposes, run it in a completely separate Chrome profile isolated from personal browsing and sensitive accounts. Consider contacting Hospitable directly for alternative integration methods. Regularly monitor the extension's behavior and remove it immediately if you notice any suspicious activity or unexpected clipboard modifications.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: clipboardWrite
This extension has the clipboardWrite permission. Can modify clipboard content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.