CRX aminer
Extension icon

Clippings.io for Amazon Kindle Highlights

Version 4.0.7 View in Chrome Web Store

Last scanned: 1 day ago | force re-scan

Extension Details

Developer: clippings.io
Rating: 4.5 ★ (453 ratings)
Users: 10,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a solid user base of 10,000 users with a strong 4.5-star rating from 453 reviews, indicating positive user experiences. The developer identity "clippings.io" aligns with the extension's purpose, suggesting legitimate ownership. The extension uses Manifest V3, which provides better security controls than older versions.

Concerns:

The primary concern is the broad host permissions that extend beyond what's necessary for the stated functionality. While access to Amazon Kindle domains (read.amazon.com, read.amazon.co.jp) is justified for extracting highlights, the extension also requests access to ext.clippings.io and localhost:8080, which could potentially be exploited. The storage permission allows data retention, which raises questions about what highlight data is stored and how it's handled. Content script injection across multiple domains creates additional attack surface.

Recommendations:

This extension appears legitimate for its intended purpose but requires careful consideration. Install only if you actively use Amazon Kindle and need highlight management functionality. Consider running it in a separate Chrome profile to isolate it from sensitive browsing activities. Review the extension's privacy policy to understand data handling practices. Monitor for any unusual behavior or requests for additional permissions in future updates. The medium risk level suggests cautious use rather than complete avoidance.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://read.amazon.com/*, https://read.amazon.co.jp/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.