Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

PayPal Honey: Automated Coupons & Rewards

bmnlcjabgnpnenekpadlanbbkooimhnj
Risk Score
3.14
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Shopping
Installs 12,000,000
Rating 4.6
Last updated 2026-08-21
Manifest version MV3
CSP present ✅ yes
Developer honey@paypal.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host access (http://*/*, https://*/*) + cookies + webRequest enables full cross-site data visibility.
  • Privacy policy not scoped to this extension and lacks data-collection/retention disclosures.
  • new Function() constructor present; context appears globalThis polyfill but still an eval-class risk.
  • 13M installs make this a high-value target if extension or supply chain is ever compromised.
  • third_party_silence in privacy policy — no statement on whether data is shared with third parties.

Evidence

  • verified_publisher + recognized_org (PayPal) store Verified publisher badge present; developer domain paypal.com resolves; confirmed brand owner.
  • broad host permissions + cookies + webRequest manifest cookies & webRequest paired with <all_urls> — ×1.2 multiplier applied; justified-broad discount applied for Shopping.
  • privacy policy not scoped to extension api fetched=true, scope_extension=false, data_collection=false → +9.0 privacy; third_party_silence adds +1.0.
  • function_constructor in merchantSPBResponders.js crx new Function() use matches globalThis polyfill pattern; +2.5 code quality per debugger_attach/function_constructor rule.
  • no CVEs, no bad hosts, no monetization/affiliate hits api cve_findings_raw=[], bad_host_hits=[], monetization_hits=[], affiliate_hits=[] — all clean.
  • recently updated, MV3, strict CSP manifest Last updated June 2026 (0 months); MV3; CSP script-src 'self' only — no unsafe-eval/inline.
  • operator cluster: no siblings api sibling_count=0 across dev_email, csp_host_set, compound fingerprints.
  • no review red flags, no ownership change store review match_count=0; wayback ownership_changed=false.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • cookies high Can read/write cookies across all sites via broad host_permissions.
  • webRequest high Observe all network requests across all URLs; paired with <all_urls>.
  • scripting medium Programmatic script injection into any page; justified for coupon application.
  • http://*/* high Broad host access to all HTTP sites enables wide content-script reach.
  • https://*/* high Broad host access to all HTTPS sites; core to Shopping category function.
  • storage low Standard local state persistence.
  • unlimitedStorage low Allows larger local data store; low direct risk.
  • alarms low Periodic background wake; minimal risk.
  • offscreen low Off-screen document for DOM tasks; limited surface.

Pillar Scores

Permissions5.10
Reputation2.00
Network2.00
Webstore2.00
Maintenance0.00
Privacy9.00
Code Quality2.50
CVE Exposure0.00

Scoring History

fsssiedxn88b55a5czan88b55a5czsssiedx 4.00 Medium review 2026-08-25
sssiedn1545ab70dp727562726963xsx 3.47 Low review 2026-08-25
sssieddrubricxsx 3.44 Low review 2026-08-15
v3.6 3.14 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 12:19
Listing SHA c3ed1437bf2d…
Force block — not fired
Score recovered no
Elapsed