CRX aminer
Extension icon

Tripadvisor: Travel Reviews & Deals on Hotels, Restaurants & Attractions

Version 1.3.0.25 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Developer: https://tripadvisor.com/
Rating: 4.6 ★ (107 ratings)
Users: 70,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: TripAdvisor is a well-established, legitimate travel company with a strong reputation. The extension has a good rating of 4.6 stars from 107 reviews and 70,000 users, indicating reasonable user satisfaction. The developer is verified as the official TripAdvisor domain, which adds credibility.
Concerns: Despite being from a reputable company, this extension requests extremely broad permissions that far exceed what's necessary for travel reviews and deals. The webRequest permission allows intercepting and modifying all web traffic, while webNavigation enables comprehensive browsing tracking. The universal host permissions (*://*/*) grant access to every website you visit, including banking, email, and other sensitive sites. The content script injection across all websites means the extension can read and modify any webpage content, potentially capturing passwords, personal information, or financial data. These permissions create a massive attack surface that could be exploited if the extension is compromised or if TripAdvisor's security practices are inadequate.
Recommendations: Run this extension in a completely separate Chrome profile dedicated only to travel-related browsing. Never use this profile for banking, email, work, or any sensitive activities. Consider whether you truly need the extension's functionality, as you can access TripAdvisor's services directly through their website. Monitor your accounts for any unusual activity. If possible, look for alternative travel extensions with more limited permissions, or simply bookmark TripAdvisor's website instead.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.