Amazon ASIN Copy
aohfjaadlbiifnnajpobdhokecjokhab
Risk Score
4.74
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension — scores maximum privacy risk.
- Brand impersonation signal: extension references Amazon brand but developer is unaffiliated gmail user.
- eval() and new Function() in bundled node_modules (sucrase, source-map-js) shipped in production CRX — code execution risk.
- innerHTML DOM-sink in src/content.js with no CSP — XSS risk on Amazon pages.
- Free-webmail developer email (gmail) with no verified publisher status raises accountability concerns.
Evidence
- privacy_policy_admits_collection_and_sharing_not_scoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (D rule).
- brand_impersonation store brand_mention.is_impersonation=true for 'amazon'; developer domain is gmail.com, confirmed_owner=false.
- eval_and_function_constructor_in_production_bundle crx eval() in sucrase RootTransformer and new Function() in source-map-js/tailwindcss shipped in extension CRX.
- dom_xss_sink_no_csp crx innerHTML assignment in src/content.js; csp_present=false raises DOM-XSS risk on Amazon pages.
- free_webmail_developer store Developer email 10xprofitio@gmail.com; not verified publisher, not featured by Google.
- no_csp_mv3 manifest content_security_policy is null; MV3 default CSP applies but no explicit hardening declared.
- maintenance_6_to_12_months store months_since_update=7; maps to +3.5 maintenance score.
- low_install_count store Only 51 installs; blast radius limited but unverified developer with high-risk policy signals.
Permissions Breakdown
- clipboardWrite medium Allows writing to clipboard; expected for ASIN copy function.
- *://*.amazon.com/* (and 20 Amazon TLD variants) medium Broad host access scoped to Amazon domains only; matches stated function.
Pillar Scores
Permissions2.30
Reputation7.50
Network0.00
Webstore3.00
Maintenance3.50
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:26
Listing SHA
88b07cd78aba…
Force block
— not fired
Score recovered
no
Elapsed
—