AiPrice(AliPrice) Search by Image for China Import
aadbahhifnekkkcbapdfandpimaoacmj
Risk Score
6.74
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- cookies + <all_urls> + scripting: can exfiltrate session cookies and inject code on every website visited.
- Privacy policy fetched but scope_extension=false AND admits 3rd-party sharing → triggers +10.0 privacy score (D rule).
- Dynamic script injection (script_src_dynamic) with no CSP; MV3 but no content_security_policy set.
- No developer name listed; identity anchored only to email hui.song@aiprice.com.
- 12 distinct external JS hosts (1688.com, taobao.com, 11st.co.kr etc.) increase data-exfil surface.
Evidence
- cookies+<all_urls>+scripting manifest cookies paired with <all_urls> and scripting; ×1.2 amplifier applied; broad shopping category gives -1.5 discount.
- privacy_policy_D_rule store Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 per v3.5 rule D.
- script_src_dynamic+no_csp crx inject-script.js dynamically creates <script> elements; no CSP defined; scores +3.0 code quality.
- function_constructor crx new Function() in vendor bundle; +2.5 code quality.
- dom_sink_innerhtml_userctrl+no_csp crx innerHTML from variable with no CSP; triggers +2.0 (FIX B: csp_present==false).
- developer_name_missing store developer_name is empty string; +1.0 reputation penalty for no 'Offered by' name.
- verified_publisher+featured store verified_publisher=true, is_featured_by_google=true; -3.0 reputation, floor 2.0 applies.
- js_external_hosts_12 crx 12 distinct external JS hosts across 1688.com, taobao.com, 11st.co.kr, interpark.com, github.com etc.
Permissions Breakdown
- activeTab low Limited to user-initiated tab interaction only.
- alarms low Scheduled tasks, low direct risk.
- contextMenus low Adds right-click menu items, minimal risk.
- cookies high Can read/write cookies across sites; paired with <all_urls> amplifies risk.
- declarativeNetRequest medium Can block/redirect network requests declaratively.
- declarativeNetRequestFeedback medium Accesses matched rule details; informational but elevates tracking capability.
- notifications low Can show desktop notifications; low direct data risk.
- scripting high Programmatic script injection into pages; combined with <all_urls> is very broad.
- <all_urls> (host) high Full host access to every site; broadest possible reach.
- http://*/* (host) high Redundant with <all_urls>; reaffirms all-HTTP access.
- https://*/* (host) high Redundant with <all_urls>; reaffirms all-HTTPS access.
- storage low Local extension storage, low risk in isolation.
Pillar Scores
Permissions7.50
Reputation3.00
Network4.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Scoring History
| sssiedn7e878cf9dp727562726963xsx | 4.79 | Medium | review | 2026-09-11 |
| sssiedn79a25a6edp727562726963xsx | 4.64 | Medium | review | 2026-09-07 |
| fsssiedxndb68c378za ndb68c378zsssiedx | 4.48 | Medium | review | 2026-08-30 |
| sssiedneeeac8eddp727562726963xsx | 4.82 | Medium | review | 2026-08-30 |
| fsssiedxn98122da9za xx pn98122da9zsssiedx | 5.58 | Medium | review | 2026-08-30 |
| sssiedn98e45129dp727562726963xsx | 4.74 | Medium | review | 2026-08-30 |
| sssieddrubricxsx | 4.86 | Medium | review | 2026-08-13 |
| v3.6 | 6.74 | High | block | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA
e5b4a4421f14…
Force block
— not fired
Score recovered
no
Elapsed
52.7s