CRX aminer
Extension icon

Surf Security 5

Version 1.4.213 View in Chrome Web Store

Last scanned: 1 day ago | force re-scan

Extension Details

Rating: 3.5 ★
Users: 2,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has concerning trust indicators with only 2,000 users and a modest 3.5-star rating. The lack of visible developer information and company details raises additional red flags. The name "Surf Security 5" suggests it's a security tool, but the extensive permissions far exceed what most legitimate security extensions require.

Concerns:

The permission set is extremely invasive and includes dangerous capabilities like proxy control, web request interception, extension management, and identity access. The combination of broad host permissions with webRequest and proxy permissions creates a perfect storm for man-in-the-middle attacks. The management permission allows it to disable other security extensions. The unsafe WebAssembly execution policy could hide malicious code. For a security extension, having access to downloads, cookies, and complete browsing history seems excessive and potentially contradictory to its stated purpose.

Recommendations:

Do not install this extension. If already installed, remove it immediately. The risk profile suggests potential malware or a compromised legitimate extension. If you absolutely need similar functionality, research well-established security extensions from reputable companies with transparent privacy policies and significantly higher user bases. Consider using built-in browser security features or dedicated security software instead. If you must test suspicious extensions, use a completely isolated browser profile or virtual machine.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: proxy
This extension has the proxy permission. Can control proxy settings. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.