CRX aminer
Extension icon

keepClipper - web clipper for google keep

Version 0.1.14 View in Chrome Web Store

Last scanned: 2 days ago | force re-scan

Extension Details

Developer: noterail.co
Rating: 3.8 ★ (6 ratings)
Users: 965

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a relatively small user base of 965 users and only 6 ratings, which limits confidence in its reliability. The 3.8-star rating is moderate but based on very few reviews. The developer "noterail.co" appears to be a smaller entity without established reputation. The extension's purpose as a web clipper for Google Keep is legitimate and the host permissions align with this functionality.

Concerns:

The primary concern is the "Broad Host Permissions" finding, though in this case the permissions are specifically scoped to Google Keep domains rather than truly broad access. The activeTab permission could potentially access sensitive information from any tab when the extension is activated. The combination of scripting and storage permissions means the extension can execute code and retain data, which requires trust in the developer's intentions and security practices.

The declarativeNetRequestWithHostAccess permission is somewhat unusual for a simple web clipper and could potentially be used to modify network requests to Google Keep.

Recommendations:

Given the medium risk level and small user base, consider running this extension in a separate Chrome profile if you handle sensitive information. Monitor the extension's behavior when clipping content to ensure it only accesses Google Keep as intended. Consider alternatives with larger user bases and more established developers if available. Regularly review what data the extension has stored and remove it if no longer needed.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://keep.google.com/*, https://notes-pa.clients6.google.com/static/proxy.html?*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.