CRX aminer

Starting analysis...

Extension icon

toast.log

Version 2.6.2 View in Chrome Web Store

Last scanned: 24 days ago | force re-scan

Extension Details

Developer: toastlog.com
Rating: 4.7 ★ (9 ratings)
Users: 1,000

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a very small user base of only 1,000 users, which limits community validation. While it maintains a decent 4.7-star rating, this is based on only 9 reviews, making it statistically insignificant. The developer domain "toastlog.com" suggests a logging or debugging tool, which aligns with the extension name. However, the lack of detailed developer information and limited adoption raises trust concerns.

Concerns:

The extension's permission set is extremely broad and concerning for what appears to be a logging utility. The combination of all_urls host permissions with content script injection capabilities creates a powerful surveillance mechanism that could access sensitive data across all websites. The storage permission allows persistent data collection, while activeTab provides additional access vectors. For a logging tool, these permissions seem excessive and could enable credential theft, session hijacking, or comprehensive browsing surveillance.

Recommendations:

Given the high-risk profile, avoid installing this extension unless absolutely necessary. If you must use it, create a dedicated Chrome profile isolated from your primary browsing activities, especially banking and sensitive sites. Consider alternative logging tools with more restricted permissions. Monitor your accounts for unusual activity if you've already installed it. The broad permissions combined with low adoption make this extension particularly risky for general use.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.