Is "Highlight multiple keywords in a web page" on Chrome Web Store Safe to Install?

[email protected] · chrome · v0.0.12

When you look for some information in many posts, articles, or announcements, it is handy to highlight relevant keywords in the web page contents. Now that it is trendy for the search engines to return inexact and irrelevant results, highlighting meaningful expressions saves time. A sample use case - searching for job offers in LinkedIn. >95% of search results do not contain the words used for the search. With this extension you do not need to read each post, you see immediately if it contains any keywords. Or imagine you search with Google. You want to highlight your keywords in the search results and the pages that open when you click the links. Or you need to black out some strings, such as you personal details, before taking screenshots. The extension is maximally simple to use. Enter once the keywords in the option page, and then click the extension icon whenever you look though the contents that are supposed to contain those text strings. To access the options, right click the extension's icon and then click options in the menu. By default the effect of the click on the extension's icon is lost on any navigation or refresh. You can choose in the options to reactivate highlighting automatically when navigation is from a page where highlighting was on. Note, highlights appear when a page is completely loaded. The extension is free and open source.

Risk Assessment

Analyzed
47.23
out of 100
MEDIUM

35 security findings detected across all analyzers

Chrome extension requesting 4 permissions

Severity Breakdown

0
Critical
13
High
22
Medium
0
Low
0
Info

Finding Categories

13
Malware Signatures
1
Network
21
IoC Indicators

YARA Rules Matched

6 rules(13 hits)
postinstall obfuscation postinstall file manipulation postinstall file download postinstall system command postinstall crypto operations postinstall network communication

Requested Permissions

4 permissions
activeTab
Medium
scripting
Low
storage
Low
webNavigation
Low

About This Extension

When you look for some information in many posts, articles, or announcements, it is handy to highlight relevant keywords in the web page contents. Now that it is trendy for the search engines to return inexact and irrelevant results, highlighting meaningful expressions saves time. A sample use case - searching for job offers in LinkedIn. >95% of search results do not contain the words used for the search. With this extension you do not need to read each post, you see immediately if it contains any keywords. Or imagine you search with Google. You want to highlight your keywords in the search results and the pages that open when you click the links. Or you need to black out some strings, such as you personal details, before taking screenshots. The extension is maximally simple to use. Enter once the keywords in the option page, and then click the extension icon whenever you look though the contents that are supposed to contain those text strings. To access the options, right click the extension's icon and then click options in the menu. By default the effect of the click on the extension's icon is lost on any navigation or refresh. You can choose in the options to reactivate highlighting automatically when navigation is from a page where highlighting was on. Note, highlights appear when a page is completely loaded. The extension is free and open source.

Detailed Findings

14 total

YARA Rule Matches

6 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
5
IP Addresses
3
Domains
15
Strings
21

All Indicators · 21

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

Domain
detected Domain: firestore.googleapis.com

XIOC detected Domain: firestore.googleapis.com

extracted_from_files

URL
detected URL: https://medium.com/@marian-caikovski/using-javascript-modules-in-content-scripts-and-extension-service-workers-e60e97979326

XIOC detected URL: https://medium.com/@marian-caikovski/using-javascript-modules-in-content-scripts-and-extension-service-workers-e60e97979326

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://chromewebstore.google.com/detail/EXTENSION_ID/support

XIOC detected URL: https://chromewebstore.google.com/detail/EXTENSION_ID/support

extracted_from_files

URL
detected URL: https://chromewebstore.google.com/detail/highlight-multiple-keywor/EXTENSION_ID

XIOC detected URL: https://chromewebstore.google.com/detail/highlight-multiple-keywor/EXTENSION_ID

extracted_from_files

URL
detected URL: https://firestore.googleapis.com/v1/projects/$

XIOC detected URL: https://firestore.googleapis.com/v1/projects/$

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

Domain
detected Domain: b.map

XIOC detected Domain: b.map

extracted_from_files

Domain
detected Domain: medium.com

XIOC detected Domain: medium.com

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

Domain
detected Domain: btn.show

XIOC detected Domain: btn.show

extracted_from_files

Domain
detected Domain: chromewebstore.google.com

XIOC detected Domain: chromewebstore.google.com

extracted_from_files

Domain
detected Domain: r.map

XIOC detected Domain: r.map

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: e.map

XIOC detected Domain: e.map

extracted_from_files

Domain
detected Domain: i.map

XIOC detected Domain: i.map

extracted_from_files

Domain
detected Domain: nodefilter.show

XIOC detected Domain: nodefilter.show

extracted_from_files

Domain
detected Domain: e.parentnode.host

XIOC detected Domain: e.parentnode.host

extracted_from_files

Domain
detected Domain: o.map

XIOC detected Domain: o.map

extracted_from_files

Domain
detected Domain: e.host

XIOC detected Domain: e.host

extracted_from_files

Security Analysis Summary

Security Analysis Overview

Highlight multiple keywords in a web page is a Chrome Web Store extension published by [email protected]. Version 0.0.12 has been analyzed by the Risky Plugins security platform, receiving a risk score of 47.23/100 (MEDIUM risk) based on 35 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 13 finding(s)
  • Medium: 22 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Highlight multiple keywords in a web page is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 2K users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions