Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shopping Cart Share

apnigoloonhabnplobkhailjllggdnll
Risk Score
6.19
Risk Level: High
Recommendation: 🚫 BLOCK
Category Shopping
Installs 2,000
Rating 2.5
Last updated 2023-10-18 (32 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@shoppingcartshare.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing (+10.0 privacy).
  • Stale 32 months with cookies+scripting+declarativeNetRequestWithHostAccess on major retail sites creates high takeover risk.
  • install_url_hijack and uninstall_url_hijack both true — suspicious redirect behavior on install/uninstall.
  • Broad host permissions cover Amazon (18 TLDs), eBay (28 TLDs), Walmart, Target, Best Buy, Staples — full cart/cookie read on checkout flows.
  • No CSP + innerHTML DOM-XSS sink in bundled JS on pages with active cookie access to retail accounts.

Evidence

  • privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, not extension-scoped; scope_extension=false, data_collection=true, third_party_sharing=true.
  • install_url_hijack + uninstall_url_hijack crx Both install_url_hijack and uninstall_url_hijack are true; targets are null (unknown redirect destinations).
  • stale_extension store Last updated October 2023, 32 months ago. No active maintenance with HIGH permissions on financial-adjacent sites.
  • cookies+scripting+declarativeNetRequestWithHostAccess on major retail manifest cookies + scripting + DNRWHA granted across Amazon (18 TLDs), eBay (28), Walmart, Target, Best Buy, Staples.
  • dom_xss_sink_no_csp crx innerHTML DOM-XSS sink in client-7693ed53.js; no CSP present, elevating exploitability on retail pages.
  • no_developer_name store developer_name is empty string; identity accountability reduced.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true: 2000 installs with HIGH-tier permissions, low visibility for abuse detection.
  • rating_2.5 store Rating 2.5 is low, though rating_count not disclosed; combined with stale state increases concern.

Permissions Breakdown

  • storage low Standard local data persistence, low risk.
  • unlimitedStorage low Allows large local storage; minimal direct risk.
  • declarativeNetRequestWithHostAccess high Can intercept/redirect network requests on all declared host origins.
  • cookies high Can read/write cookies on all declared host origins including major retailers.
  • activeTab medium Access to current tab content on user interaction.
  • scripting high Can inject scripts into pages on declared host origins (Amazon, Walmart, eBay, etc.).
  • host_permissions (amazon/walmart/ebay/target/bestbuy/staples multi-domain) high Broad access to major retail/financial-adjacent sites including cart and account pages.

Pillar Scores

Permissions6.50
Reputation5.50
Network2.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

v3.6 6.19 High block 2026-06-16
v3.4-rev 5.34 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA 06dcb374bd86…
Force block — not fired
Score recovered no
Elapsed 27.3s