CRX aminer

Starting analysis...

Extension icon

Amazon Price Tracker

Version 1.1 View in Chrome Web Store

Last scanned: 9 months ago | force re-scan

Extension Details

Rating: 4.5 ★ (8 ratings)
Users: 661

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a very small user base of only 661 users, which limits community validation. While it maintains a decent 4.5-star rating, this is based on only 8 reviews, making it statistically insignificant. The lack of developer information and company details raises transparency concerns. The extension targets a legitimate use case (Amazon price tracking) but operates with minimal oversight.

Concerns:

The most significant red flag is the broad host permissions (*://*/*) which grants access to all websites, far exceeding what's necessary for Amazon price tracking. The tabs permission allows manipulation of browser tabs and access to sensitive tab information. While the content scripts are appropriately scoped to Amazon domains, the overly broad host permissions create unnecessary attack surface. The combination of storage, notifications, and extensive web access could enable data collection beyond the stated purpose.

Recommendations:

Given the high risk profile, consider running this extension in a separate Chrome profile to isolate potential security impacts. The broad permissions are disproportionate to the functionality - a legitimate Amazon price tracker should only need access to Amazon domains. Look for alternative extensions with more restrictive permissions and larger user bases. If you must use this extension, regularly review your stored data and be cautious about sensitive browsing while it's active. Consider disabling it when not actively price tracking on Amazon.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.