Shopify SHARK - Product scraper & store spy
aingngcmeghkkpbapgdhbidmemoiaahb
Risk Score
4.59
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: extension name prominently features 'Shopify' but developer is not Shopify (confirmed_owner=false).
- Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true — worst-case policy disclosure (+10.0).
- Extension is 27 months stale (last updated March 2024), placing it in the high-maintenance-risk band.
- Install URL hijack: onInstalled opens third-party landing page at hypercavs.com (+2.0 webstore).
- No content_security_policy on MV3 extension that contacts external host and uses scripting permission.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=['shopify'], confirmed_owner=false; developer is hypercavs.com.
- privacy_policy_scope_mismatch api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true — generic policy admitting sharing.
- install_url_hijack crx install_url_hijack=true; opens https://hypercavs.com/shopify-shark/index.html?chn=chrome-extension on install.
- stale_extension store months_since_update=27; falls in 24-36mo band (+8.5 maintenance).
- no_csp manifest content_security_policy=null; MV3 default CSP applies but no explicit policy declared.
- no_developer_name store developer_name is empty string; raises reputation uncertainty.
- scripting_permission manifest scripting declared; allows programmatic injection into pages visited by user.
- cve_findings_empty crx No CVEs detected in bundled JS libraries; cve_findings_raw=[].
Permissions Breakdown
- activeTab low Grants access only to the current tab when user invokes the extension.
- identity medium Can access OAuth tokens; risk depends on scopes requested at runtime.
- storage low Local key-value storage only; no cross-origin exfil by itself.
- scripting medium Allows programmatic script injection into pages; broad when combined with host perms.
- https://hypercavs.com/ low Narrow host permission scoped to developer's own domain only.
Pillar Scores
Permissions2.60
Reputation7.00
Network2.00
Webstore6.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA
22abba9a38a5…
Force block
— not fired
Score recovered
no
Elapsed
22.1s