Reviews for Check Trustpilot
Check Trustpilot by gavinhow
1 review
- Rated 2 out of 5by gammy, 2 days agoLovely idea, but dangerously - needlessly - insecure.
Don't install this.
Every single website you visit is sent to Trustpilot in real-time, which is probably not what most people expect, and it is an immense security leak.
Gavin, can you perform the request when a trust-score is explicitly requested instead, as people expect?
The extension-icon tool-tip says "Check Trustpilot" after all, but that's not what it does; it just shows the information it already fetched in the background.
Looking up the Trustpilot score only upon clicking on the icon would completely eliminate this problem.
Please make this change.
I understand that doing this would incur a minor delay as the score isn't preemptively fetched, but I think people would find that preferable to leaking all domains visited. If you really find this intolerable, make it configurable with a clearly visible checkbox, ideally defaulting to the safe behavior.
This extension would be absolutely brilliant if this change was implemented. It's an excellent idea, and the presentation is really nice and succinct. It has other minor problems as others have pointed out (only checking the UK site at the time of writing), but I think with enough traction, Gavin could add more sites.
To other readers: Verify this unsafe behavior for yourself: Open the browser console (ctrl+shift+j), set 'Console Mode' to 'Mutiprocess'. Mark 'Requests' and 'XHR' (i.e javascript requests), then filter on 'trustpilot'. Observe the log as you go to various websites.
This review was written when the latest extension version is 0.1.1 - if a newer version exists, please check the behavior yourself and add a comment if this concern is no longer relevant! I really hope that the extension is updated so that I can leave a positive review and - more importantly - be an extension I will use.