Security Warning: High Security Risk
CRX Loader
ID: chokhpikgifdgmfipekibjgnhhmkddon
Supported Languages
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- crxloader.comView Profile
- Privacy
- Privacy Policy
- Help
- Help Center
- Website
- Visit
Install and manage Chrome extensions from CRX or ZIP files in a secure loader workspace.
The bundled manifest declares `optional_host_permissions: ["*://*/*"]`, which is entirely absent from the published CWS manifest summary. This field would allow the extension to request host access to every URL on the internet; when combined with the declared `scripting` permission and `declarativeNetRequestWithHostAccess`, it means any user who grants these optional permissions gives the extension the ability to inject JavaScript into and rewrite network requests for every site they visit. The omission from the CWS-disclosed manifest is itself a disclosure violation.
{ "optional_host_permissions": [ "*://*/*" ]}By severity
Versions scanned
None of the 3 scanned versions have more than one unique code-review finding. Counts are unique findings that include each version.
| Extension Version | Code Review Findings |
|---|---|
| No versions with multiple unique findings. | |
Files with findings
1 distinct path โ top paths by unique finding count:
- manifest.json1
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
Gain full insight into all external connections.
Upgrade for full visibility.
Gain full insight into all external connections.
Upgrade for full visibility.
Code Diff
Compare extension code between any two versions.
No comparable text files found between these versions.
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.
