CRX aminer
Extension icon

Tripadvisor: Travel Reviews & Deals on Hotels, Restaurants & Attractions

Version 1.3.0.21 View in Chrome Web Store

Last scanned: 3 months ago | force re-scan

Extension Details

Developer: https://tripadvisor.com/
Rating: 4.6 ★ (107 ratings)
Users: 60,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: The extension comes from TripAdvisor, a well-established travel company with a legitimate business model. The 4.6-star rating from 107 reviews and 60,000 users suggest reasonable user satisfaction. However, the user base is relatively small for such a major brand, which may indicate limited adoption or newer release.
Concerns: The extension's permissions are extremely broad and concerning for a travel review tool. The webRequest permission allows intercepting and modifying all web traffic, while webNavigation enables comprehensive browsing tracking. The universal host permissions (*://*/*) grant access to every website you visit, far exceeding what's necessary for showing travel reviews. Content script injection across all sites creates potential for credential theft or sensitive data access. The unlimitedStorage permission could enable extensive data collection. These capabilities are disproportionate to the extension's stated purpose of providing travel reviews and deals.
Recommendations: Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile specifically for travel-related browsing and limit sensitive activities in that profile. Consider using TripAdvisor's website directly instead, as it provides the same functionality without requiring such invasive permissions. The broad permissions suggest potential data collection beyond what's necessary for the extension's core features.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.