CRX aminer

Starting analysis...

Extension icon

PayPal Honey: Automated Coupons & Rewards

Version 19.3.0 View in Chrome Web Store

Last scanned: 9 days ago | force re-scan

Extension Details

Developer: https://www.joinhoney.com/
Rating: 4.6 ★ (179.8K ratings)
Users: 13,000,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors: PayPal Honey is a legitimate extension from a reputable company (PayPal/Honey Science Corporation) with an impressive 13 million users and strong 4.6-star rating from nearly 180,000 reviews. The extension's core functionality of finding and applying coupon codes requires access to e-commerce websites, which explains many of its permissions. Being owned by PayPal adds significant credibility to the extension's trustworthiness.
Concerns: The extension requests several powerful permissions that could be concerning in the wrong hands. The cookies permission allows reading and modifying browser cookies across all websites, which could expose session data. The webRequest permission enables intercepting and potentially modifying web traffic. The broad host permissions (all HTTP/HTTPS sites) mean the extension can access every website you visit. While these permissions align with Honey's coupon-finding functionality, they create a large attack surface if the extension were compromised.
Recommendations: Given the extension's legitimate purpose and strong reputation, the risk is manageable for most users. However, privacy-conscious users should be aware that Honey collects browsing data for its business model. Consider reviewing Honey's privacy policy to understand data collection practices. If you're particularly security-focused, you could run this extension in a separate Chrome profile used only for shopping, limiting its access to sensitive browsing activities like banking or work-related sites.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.