CRX aminer

Starting analysis...

Extension icon

Add to CRM for Freshworks: Free B2B Prospecting Integration

Version 5.2.5 View in Chrome Web Store

Last scanned: 3 months ago | force re-scan

Extension Details

Rating: 5.0 ★
Users: 58

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has very limited adoption with only 58 users and a perfect 5.0 rating, though the small sample size makes this rating less meaningful. The extension targets Freshworks CRM integration for B2B prospecting, which is a legitimate business use case. However, the lack of detailed developer information and minimal user base raises concerns about the extension's maturity and trustworthiness.

Concerns:

The extension requests extremely broad permissions that far exceed what's necessary for basic CRM integration. The tabs permission allows manipulation of all browser tabs, not just the active one, which is excessive for a prospecting tool. Host permissions span multiple sensitive platforms including LinkedIn, Gmail, and Outlook, creating significant attack surface. The inclusion of localhost permissions suggests development/testing code may still be present in the production version. Content scripts can inject code across all these sensitive domains, potentially intercepting confidential business communications and contact data.

Recommendations:

Given the high risk level, run this extension in a separate Chrome profile dedicated to prospecting activities only. Avoid using this profile for sensitive business communications or accessing confidential information. Consider using established CRM tools with better security track records and larger user bases. If you must use this extension, regularly audit what data it's accessing and storing, and remove it immediately after use rather than keeping it permanently installed.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: https://www.linkedin.com/*, https://mail.google.com/*, https://outlook.office.com/*, https://outlook.office365.com/*, https://outlook.live.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.