This extension requests significant permissions. It has 1M+ users, a 3.5 star rating, is published by Little Void LLC, but review the findings below.
This extension shows some risk signals that are common in legitimate extensions but worth reviewing. Check the details below.
Based on 9 permissions analyzed, 52 code findings, 1 dangerous combination.
Extension uses tab tracking APIs (onUpdated/query) and communicates with external servers — potential browsing surveillance.
1 library detected
The 'unsafe-eval' source allows eval(), new Function(), and similar dynamic code execution — a major code injection risk.
The 'unsafe-inline' source allows inline <script> tags and event handlers, enabling script injection attacks.
object-src is not set to 'none'. Plugins like Flash can be embedded, which may allow code execution.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
12 indicators of compromise found