Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AiPrice(AliPrice) Search by Image for China Import

aadbahhifnekkkcbapdfandpimaoacmj
Risk Score
6.74
Risk Level: High
Recommendation: 🚫 BLOCK
Category Shopping
Installs 100,000
Rating 4.9
Last updated 2026-08-15 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer hui.song@aiprice.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + <all_urls> + scripting: can exfiltrate session cookies and inject code on every website visited.
  • Privacy policy fetched but scope_extension=false AND admits 3rd-party sharing → triggers +10.0 privacy score (D rule).
  • Dynamic script injection (script_src_dynamic) with no CSP; MV3 but no content_security_policy set.
  • No developer name listed; identity anchored only to email hui.song@aiprice.com.
  • 12 distinct external JS hosts (1688.com, taobao.com, 11st.co.kr etc.) increase data-exfil surface.

Evidence

  • cookies+<all_urls>+scripting manifest cookies paired with <all_urls> and scripting; ×1.2 amplifier applied; broad shopping category gives -1.5 discount.
  • privacy_policy_D_rule store Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 per v3.5 rule D.
  • script_src_dynamic+no_csp crx inject-script.js dynamically creates <script> elements; no CSP defined; scores +3.0 code quality.
  • function_constructor crx new Function() in vendor bundle; +2.5 code quality.
  • dom_sink_innerhtml_userctrl+no_csp crx innerHTML from variable with no CSP; triggers +2.0 (FIX B: csp_present==false).
  • developer_name_missing store developer_name is empty string; +1.0 reputation penalty for no 'Offered by' name.
  • verified_publisher+featured store verified_publisher=true, is_featured_by_google=true; -3.0 reputation, floor 2.0 applies.
  • js_external_hosts_12 crx 12 distinct external JS hosts across 1688.com, taobao.com, 11st.co.kr, interpark.com, github.com etc.

Permissions Breakdown

  • activeTab low Limited to user-initiated tab interaction only.
  • alarms low Scheduled tasks, low direct risk.
  • contextMenus low Adds right-click menu items, minimal risk.
  • cookies high Can read/write cookies across sites; paired with <all_urls> amplifies risk.
  • declarativeNetRequest medium Can block/redirect network requests declaratively.
  • declarativeNetRequestFeedback medium Accesses matched rule details; informational but elevates tracking capability.
  • notifications low Can show desktop notifications; low direct data risk.
  • scripting high Programmatic script injection into pages; combined with <all_urls> is very broad.
  • <all_urls> (host) high Full host access to every site; broadest possible reach.
  • http://*/* (host) high Redundant with <all_urls>; reaffirms all-HTTP access.
  • https://*/* (host) high Redundant with <all_urls>; reaffirms all-HTTPS access.
  • storage low Local extension storage, low risk in isolation.

Pillar Scores

Permissions7.50
Reputation3.00
Network4.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Scoring History

sssiedn7e878cf9dp727562726963xsx 4.79 Medium review 2026-09-11
sssiedn79a25a6edp727562726963xsx 4.64 Medium review 2026-09-07
fsssiedxndb68c378za ndb68c378zsssiedx 4.48 Medium review 2026-08-30
sssiedneeeac8eddp727562726963xsx 4.82 Medium review 2026-08-30
fsssiedxn98122da9za xx pn98122da9zsssiedx 5.58 Medium review 2026-08-30
sssiedn98e45129dp727562726963xsx 4.74 Medium review 2026-08-30
sssieddrubricxsx 4.86 Medium review 2026-08-13
v3.6 6.74 High block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA e5b4a4421f14…
Force block — not fired
Score recovered no
Elapsed 52.7s