CRX aminer
Extension icon

Zendesk Download Router

Version 4.4.0 View in Chrome Web Store

Last scanned: 3 days ago | force re-scan

Extension Details

Rating: 4.8 ★ (10 ratings)
Users: 711

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension has a very small user base of only 711 users, which limits community validation. However, it maintains a high rating of 4.8/5 from 10 reviews, suggesting satisfied users within its niche. The extension targets Zendesk users specifically, indicating a legitimate business use case. The lack of developer information and company details reduces transparency and accountability.

Concerns:

The extension requests several powerful permissions that exceed typical requirements for a download router. The downloads permission allows access to download history and file manipulation capabilities. The tabs permission grants broad access to browser tab information and control, which seems excessive for routing downloads. The activeTab permission, while more reasonable, still provides access to sensitive page content. Content scripts run on Zendesk domains, which could access sensitive customer support data and communications.

Recommendations:

Given the high-risk permissions and limited user base, consider running this extension in a separate Chrome profile dedicated to Zendesk work. This isolates potential security risks from your main browsing profile. Before installation, verify the extension's legitimacy through Zendesk's official channels or community forums. Monitor the extension's behavior closely, particularly regarding file downloads and tab interactions. Consider whether the functionality truly requires such broad permissions, and explore alternative solutions if available. Regularly review installed extensions and remove this one if it's no longer essential to your workflow.

Findings

HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.