CRX aminer

Starting analysis...

Extension icon

Calendly: Meeting Scheduling Software

Version 4.12.0.0 View in Chrome Web Store

Last scanned: 21 days ago | force re-scan

Extension Details

Developer: Calendly LLC
Rating: 4.3 ★ (153 ratings)
Users: 700,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

Calendly is a well-established, legitimate company with a widely-used scheduling platform. The extension has 700,000 users and a solid 4.3-star rating, indicating general user satisfaction. The developer is clearly identified as Calendly LLC, which adds credibility. The extension serves a legitimate business purpose for meeting scheduling integration.

Concerns:

The extension's broad permissions are concerning given its stated purpose. The <all_urls> host permissions and content script injection capabilities allow access to every website you visit, which is excessive for a scheduling tool. While some specific integrations (Gmail, Google Calendar, LinkedIn) make sense for scheduling functionality, the unlimited web access creates significant privacy and security risks. The unlimitedStorage permission could allow extensive data collection and storage without user awareness.

Recommendations:

Consider using Calendly's web interface directly instead of the extension when possible. If you must use the extension, install it in a separate Chrome profile dedicated to work activities to limit exposure of personal browsing. Regularly review what data the extension has access to through Chrome's privacy settings. Monitor for any unusual behavior or unexpected website modifications. Given Calendly's legitimate business model, the risk is primarily from potential data collection rather than malicious intent, but the broad permissions still warrant caution.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.