CRX aminer
Extension icon

BugHerd: Visual Feedback & Bug Tracking Tool

Version 3.0.4825 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Developer: Splitrock Studio Pty Ltd
Rating: 4.3 ★ (45 ratings)
Users: 80,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

BugHerd appears to be a legitimate visual feedback and bug tracking tool from Splitrock Studio Pty Ltd, with 80,000 users and a solid 4.3-star rating. The company has an established presence in the web development tools space, which adds credibility. However, the extension's extensive permissions create significant security exposure despite its legitimate business purpose.

Concerns:

The extension's permission set is extremely broad and concerning. Access to all URLs, tabs, web navigation tracking, and cookie manipulation creates a comprehensive surveillance capability. The ability to inject content scripts into any website means it can read sensitive data, modify page content, or potentially capture credentials across all browsing activity. While these permissions may be necessary for bug tracking functionality, they create substantial privacy and security risks. The declarativeNetRequest permission adds another layer of network-level control that could be misused.

Recommendations:

Given the critical risk level, consider running this extension in a completely separate Chrome profile dedicated solely to development work. Only enable it when actively conducting bug tracking or feedback collection activities. Regularly audit what data the extension collects and ensure your organization has proper data handling agreements with Splitrock Studio. Consider alternative bug tracking solutions with more limited permissions if the broad access isn't essential for your workflow. Monitor network activity when the extension is active to ensure it's only communicating with expected BugHerd services.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: <all_urls>
This extension has the <all_urls> permission. Can access all websites and their content. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.