CRX aminer

Starting analysis...

Extension icon

max PayBack Reminder - מקס פייבק

Version 2.2310.01.44 View in Chrome Web Store

Last scanned: 17 days ago | force re-scan

Extension Details

Developer: http://pay-back.co.il/
Rating: 2.2 ★ (86 ratings)
Users: 50,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: The extension has a concerning trust profile with only 50,000 users and a very low rating of 2.2 out of 5 stars from 86 reviews, indicating significant user dissatisfaction. The developer appears to be associated with pay-back.co.il, suggesting it's related to a cashback or rewards service, but the poor ratings raise questions about the extension's quality and reliability.
Concerns: The extension requests extremely broad permissions that seem excessive for a typical cashback reminder service. The combination of management permissions (allowing control over other extensions), tabs access, and universal host permissions creates a powerful surveillance and control capability. The management permission is particularly concerning as it's rarely needed for legitimate extensions and could be used to disable security extensions or install malicious ones. The broad host permissions combined with tabs access could enable comprehensive tracking of browsing behavior across all websites.
Recommendations: Given the high risk level and poor user ratings, avoid installing this extension. If the cashback functionality is essential, consider running it in a completely separate Chrome profile with no access to personal accounts or sensitive data. Monitor the extension closely for any suspicious behavior and regularly review what other extensions might be affected by its management permissions. Consider alternative cashback extensions with better ratings and more limited permissions. The combination of broad permissions and poor user feedback suggests this extension may not be trustworthy for handling financial or personal information.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.