Is "Amazon Fake Review Skimmer" on Chrome Web Store Safe to Install?

[email protected] · chrome · v1.2.1

Amazon Fake Review Skimmer scans Amazon product reviews and highlights suspicious ones that appear fake or incentivized. Uses pattern analysis to identify review clusters, verified purchase ratios, and reviewer behavior to give you confidence scores.

Risk Assessment

Analyzed
62.21
out of 100
MEDIUM

64 security findings detected across all analyzers

Chrome extension requesting 2 permissions

Severity Breakdown

0
Critical
0
High
53
Medium
11
Low
0
Info

Finding Categories

2
Network
51
IoC Indicators

YARA Rules Matched

5 rules(11 hits)
postinstall system command postinstall network communication postinstall file download NoUseWeakRandom postinstall crypto operations

Requested Permissions

2 permissions
activeTab
Medium
storage
Low

About This Extension

Amazon Fake Review Skimmer scans Amazon product reviews and highlights suspicious ones that appear fake or incentivized. Uses pattern analysis to identify review clusters, verified purchase ratios, and reviewer behavior to give you confidence scores.

Detailed Findings

13 total

YARA Rule Matches

5 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
12
IP Addresses
7
Domains
34
Strings
51

All Indicators · 51

IP
detected IP: ::bef

XIOC detected IP: ::bef

extracted_from_files

Domain
detected Domain: sporlyworks.com

XIOC detected Domain: sporlyworks.com

extracted_from_files

URL
detected URL: https://sporlyworks.com/

XIOC detected URL: https://sporlyworks.com/

extracted_from_files

URL
detected URL: https://github.com/daveestaaqui/micro-assets-landing-page/issues/new?title=Bug+Report&body=Extension:+Amazon

XIOC detected URL: https://github.com/daveestaaqui/micro-assets-landing-page/issues/new?title=Bug+Report&body=Extension:+Amazon

extracted_from_files

URL
detected URL: https://chromewebstore.google.com/search/SporlyWorks

XIOC detected URL: https://chromewebstore.google.com/search/SporlyWorks

extracted_from_files

URL
detected URL: https://buy.stripe.com/cNi28r8yqePFce92tM0ZW0A?client_reference_id=

XIOC detected URL: https://buy.stripe.com/cNi28r8yqePFce92tM0ZW0A?client_reference_id=

extracted_from_files

URL
detected URL: https://microassets-license-server-production.up.railway.app/poll?uuid=$

XIOC detected URL: https://microassets-license-server-production.up.railway.app/poll?uuid=$

extracted_from_files

URL
detected URL: https://microassets-license-server-production.up.railway.app/validate?key=$

XIOC detected URL: https://microassets-license-server-production.up.railway.app/validate?key=$

extracted_from_files

URL
detected URL: https://chrome.google.com/webstore/detail/'

XIOC detected URL: https://chrome.google.com/webstore/detail/'

extracted_from_files

Domain
detected Domain: jzܬ.yt

XIOC detected Domain: jzܬ.yt

extracted_from_files

Domain
detected Domain: h.pw

XIOC detected Domain: h.pw

extracted_from_files

Domain
detected Domain: ܯ.ye

XIOC detected Domain: ܯ.ye

extracted_from_files

URL
detected URL: https://daveestaaqui.github.io/micro-assets-landing-page/feedback.html

XIOC detected URL: https://daveestaaqui.github.io/micro-assets-landing-page/feedback.html

extracted_from_files

Domain
detected Domain: microassets-license-server-production.up.railway.app

XIOC detected Domain: microassets-license-server-production.up.railway.app

extracted_from_files

URL
detected URL: https://sporlyworks.com

XIOC detected URL: https://sporlyworks.com

extracted_from_files

URL
detected URL: https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap');

XIOC detected URL: https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap');

extracted_from_files

Domain
detected Domain: kк.sy

XIOC detected Domain: kк.sy

extracted_from_files

Domain
detected Domain: փ.ba

XIOC detected Domain: փ.ba

extracted_from_files

Domain
detected Domain: z.dz

XIOC detected Domain: z.dz

extracted_from_files

Domain
detected Domain: q.tz

XIOC detected Domain: q.tz

extracted_from_files

Domain
detected Domain: x.cn

XIOC detected Domain: x.cn

extracted_from_files

Domain
detected Domain: l.eu

XIOC detected Domain: l.eu

extracted_from_files

Domain
detected Domain: vr.bg

XIOC detected Domain: vr.bg

extracted_from_files

Domain
detected Domain: f.ar

XIOC detected Domain: f.ar

extracted_from_files

Domain
detected Domain: q.cf

XIOC detected Domain: q.cf

extracted_from_files

Domain
detected Domain: vg4p.cx

XIOC detected Domain: vg4p.cx

extracted_from_files

Domain
detected Domain: r.cx

XIOC detected Domain: r.cx

extracted_from_files

Domain
detected Domain: gp.cf

XIOC detected Domain: gp.cf

extracted_from_files

Domain
detected Domain: i.cu

XIOC detected Domain: i.cu

extracted_from_files

Domain
detected Domain: c.cu

XIOC detected Domain: c.cu

extracted_from_files

Domain
detected Domain: chrome.runtime.id

XIOC detected Domain: chrome.runtime.id

extracted_from_files

Domain
detected Domain: r.ma

XIOC detected Domain: r.ma

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: self.id

XIOC detected Domain: self.id

extracted_from_files

Domain
detected Domain: 5.am

XIOC detected Domain: 5.am

extracted_from_files

Domain
detected Domain: r.tj

XIOC detected Domain: r.tj

extracted_from_files

Domain
detected Domain: wt.sa

XIOC detected Domain: wt.sa

extracted_from_files

Domain
detected Domain: chromewebstore.google.com

XIOC detected Domain: chromewebstore.google.com

extracted_from_files

IP
detected Domain: buy.stripe.com

XIOC detected Domain: buy.stripe.com

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

Domain
detected Domain: window.open

XIOC detected Domain: window.open

extracted_from_files

Domain
detected Domain: btnverify.click

XIOC detected Domain: btnverify.click

extracted_from_files

Domain
detected Domain: browser.storage

XIOC detected Domain: browser.storage

extracted_from_files

Domain
detected Domain: browser.runtime.id

XIOC detected Domain: browser.runtime.id

extracted_from_files

IP
detected IP: ::9

XIOC detected IP: ::9

extracted_from_files

IP
detected IP: 6::

XIOC detected IP: 6::

extracted_from_files

IP
detected IP: ::b

XIOC detected IP: ::b

extracted_from_files

IP
detected IP: ::6

XIOC detected IP: ::6

extracted_from_files

Domain
detected Domain: daveestaaqui.github.io

XIOC detected Domain: daveestaaqui.github.io

extracted_from_files

Domain
detected Domain: a-section.review

XIOC detected Domain: a-section.review

extracted_from_files

URL
detected URL: https://chromewebstore.google.com/search/OmniSuite',

XIOC detected URL: https://chromewebstore.google.com/search/OmniSuite',

extracted_from_files

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-22. The review verdict is benign but powerful with 75% confidence.

Recommended action: monitor.
Risk context: MEDIUM risk, score 62/100.
Evidence context: threat category none; evidence quality moderate.

Extension Overview

Amazon Fake Review Skimmer (v1.2.1) is a Chrome extension with 1 user that claims to "highlight potentially suspicious reviews on Amazon product pages using heuristic analysis of review patterns and language." The developer is listed as [email protected], a generic Gmail address without corporate attribution.

Security Findings Analysis

The findings bundle shows an empty findings_by_category object, meaning the CVEQ analysis detected zero security issues across all categories: no malware signatures, no code-smell patterns, no suspicious IoCs (domains/IPs), no obfuscation indicators, and no browser hijacking behavior. This is significant evidence that the extension does not contain malicious code.

Risk Assessment

The extension's stated purpose is legitimate: helping users identify fake Amazon reviews. This is a common use case for browser extensions that read page content. The absence of findings suggests the code is straightforward and does not include:

  • Data exfiltration mechanisms
  • Credential harvesting
  • Browser hijacking (search engine manipulation, new tab replacement)
  • Network connections to suspicious domains
  • Obfuscated payloads

However, the extension has only 1 user and uses a personal Gmail address as the developer. These are weak signals that could indicate a throwaway extension or a new project. The developer name [email protected] has no connection to Amazon or review analysis expertise, which is unusual but not inherently malicious.

Counterargument Addressed

A skeptic might argue that the empty findings object could mean the analysis failed to run properly, or that sophisticated malware evaded detection. However, the evidence structure shows findings_by_category: {} rather than missing data, indicating the analysis executed and found nothing. Additionally, the version is specified as 1.2.1 (not 'unknown'), and the extension metadata is complete. If this were evasion, we would expect at least some code-smell findings from basic patterns, which are absent. The verdict is based on the absence of evidence rather than evidence of absence, but given the benign stated purpose and zero findings, the risk profile is low.

Key Reasons

  • Zero security findings across all categories (malware, code-smell, IoCs, obfuscation)
  • Legitimate stated purpose (fake review detection on Amazon)
  • Generic Gmail developer address with no corporate attribution
  • Extremely low user count (1 user) limits behavioral assessment

Frequently Asked Questions