CRX aminer

Starting analysis...

Extension icon

Fonts Ninja

Version 8.0.4 View in Chrome Web Store

Last scanned: 24 days ago | force re-scan

Extension Details

Developer: fonts.ninja
Rating: 4.4 ★ (877 ratings)
Users: 900,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

Fonts Ninja appears to be a legitimate typography tool with a substantial user base of 900,000 users and a solid 4.4-star rating from 877 reviews. The extension is developed by fonts.ninja, which suggests it's from the official company behind the service. The high user adoption and positive ratings indicate general user satisfaction and suggest the extension delivers on its promised functionality.

Concerns:

The primary concern is the combination of broad host permissions with tabs access, creating an extensive attack surface. While font identification legitimately requires access to webpage content across all sites, the tabs permission allows manipulation of browser tabs beyond what's typically necessary for font analysis. The activeTab permission would be more appropriate for this use case. The storage permission, while reasonable for saving font preferences, adds another data collection point. The broad host permissions mean this extension can access sensitive information on banking, email, and other private websites.

Recommendations:

Consider running this extension in a separate Chrome profile dedicated to design work to limit exposure of sensitive browsing activities. Regularly review what data the extension might be collecting through its storage capabilities. Monitor for any unusual tab behavior or unexpected website interactions. If you only need font identification occasionally, consider disabling the extension when not in use and enabling it only for specific design tasks. Alternative extensions with more restrictive permissions might be worth exploring for users with high security requirements.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.