Is "SnapLab" on Chrome Web Store Safe to Install?
SnapLab 是一款网页助手插件,旨在提升您的在线体验,目前专注于强大的图片处理功能。 它允许您直接在当前网页上预览图片,而无需打开新标签页。通过无缝的交互,您可以毫不费力地对图片进行缩放、旋转和翻转。 无论您是在浏览社交媒体、阅读文章还是寻找灵感,SnapLab 都能确保图片以您期望的方式快速、流畅地呈现。 虽然我们目前优先处理图片相关功能,但我们正在扩展以支持更多网页元素(如链接)和高级内容处理工具。未来将推出图片美化、格式转换、增强型网页工具等更多强大功能,不断改进您的使用体验。 使用 SnapLab,体验更快速、更直观的网页浏览方式。
Risk Assessment
Analyzed5 security findings detected across all analyzers
Chrome extension requesting 4 permissions
Severity Breakdown
Finding Categories
Requested Permissions
4 permissionsAccess and modify data on every website you visit
About This Extension
Detailed Findings
5 totalAI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-28. The review verdict is likely false positive with 75% confidence.
Recommended action: suppress false positive.
Risk context: MEDIUM risk, score 59/100.
Evidence context: threat category none; evidence quality moderate.
SnapLab is a Chinese web assistant extension (developer: [email protected]) designed for image preview, zoom, and rotation functionality. The evidence bundle contains 5 findings across 3 categories, but none indicate confirmed malicious behavior.
Network Activity: The extension declares 3 fetch calls in content-scripts/content.js:1, content-scripts/content.js:2, and background.js:1. However, the findings summary explicitly shows "ioc":"0" — no suspicious domains were extracted. Generic fetch calls without identifiable malicious destinations are common in legitimate extensions that need to communicate with their own services or APIs.
Obfuscation Finding: The high-severity OBFUSCATION-UNICODE_HEAVY flag in content-scripts/content.js:1 is the most concerning signal. However, this is likely a false positive. The extension's description is in Chinese ("网页助手插件,包含图片预览、缩放、旋转等图片处理相关功能"), and Chinese characters are Unicode-heavy by nature. The CVEQ guidelines explicitly note that zero-width Unicode characters in locale/i18n files for non-Latin scripts are legitimate, not steganography. While this finding is in a JS file rather than a locale file, the presence of Chinese text in a Chinese-language extension reasonably explains the unicode_heavy detection.
Manifest Permissions: The MANIFEST-SENSITIVE-PERM-TABS finding in manifest.json is medium severity. The tabs permission is sensitive but legitimate for a web assistant that needs to interact with page content for image processing.
Critical Absences: No malware signatures ("malware-signature":"0"), no suspicious IoC domains, no credential-access patterns, and no code-smell findings. The findings summary shows "code-smell":"0" and "malware":"0", which is significant.
Counterargument: A skeptic would argue that the combination of high-severity obfuscation, anonymous developer (gmail address), and zero users suggests a potentially malicious extension in early deployment. However, this reasoning fails to account for the lack of any actual malicious indicators. Obfuscation alone without malware signatures or suspicious network destinations does not constitute evidence of harm. The unicode_heavy pattern in a Chinese-language extension is a documented false-positive pattern. The zero user count and early version (0.0.11) indicate this is likely a developer's test extension rather than a deployed threat.
The verdict is likely_false_positive because the findings are explainable by benign factors (Chinese text triggering unicode detection, legitimate fetch calls without malicious destinations) and lack the corroborating evidence required for a malicious verdict (malware signatures, suspicious domains, credential theft patterns).
Key Reasons
- No malware signatures or suspicious IoC domains detected
- Unicode_heavy finding likely triggered by Chinese language content
- Generic fetch calls without malicious destinations
- Extension description matches stated image-processing functionality
- No code-smell or credential-access findings present
False Positive Considerations
- Unicode-heavy detection triggered by Chinese text in extension
- Generic fetch calls without suspicious domain extraction
- No malware signatures or credential-access patterns found
- Zero IoC domains extracted despite network activity
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Clearly - History Cleaner
[email protected]
Ship Xanh copy sản phẩm, nhân bản shop, hiển thị % phí sàn, lượt bán tháng
[email protected]
Auto Gmail - ChatGPT AI for email inbox
[email protected]
Dodl Notes: Teacher Anecdotal Notes
[email protected]
Research Notes
[email protected]
SVG to AVIF Converter [ShiftShift]
[email protected]