CRX aminer
Extension icon

FastSave

Version 3.8.8 View in Chrome Web Store

Last scanned: about 10 hours ago

Extension Details

Developer: spector.net
Rating: 3.4 ★ (339 ratings)
Users: 100,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a moderate user base of 100,000 users, which provides some validation through adoption. However, the relatively low rating of 3.4 out of 5 stars from 339 reviews suggests user dissatisfaction or potential issues. The developer "spector.net" lacks clear company information or established reputation, which reduces trustworthiness. The missing description is particularly concerning as users cannot understand what the extension actually does.

Concerns:

The extension requests an excessive array of permissions that appear disproportionate for most legitimate use cases. The combination of webRequest interception, cookie access, and broad host permissions creates a perfect storm for data harvesting or malicious activity. Content script injection across all websites enables the extension to read sensitive information like passwords, financial data, and personal communications. The downloads permission combined with system.display access could facilitate unauthorized file downloads or screen monitoring. The lack of transparency in the extension's description makes it impossible to verify if these permissions are justified.

Recommendations:

Do not install this extension due to its critical risk level. If you must use it, run it in a completely isolated Chrome profile with no access to personal accounts or sensitive websites. Consider seeking alternative extensions with more transparent descriptions and narrower permission scopes. The combination of broad permissions, low ratings, and missing description strongly suggests this extension poses significant security and privacy risks.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.