PayPal Honey: Automated Coupons & Rewards
bmnlcjabgnpnenekpadlanbbkooimhnj
Risk Score
3.14
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Broad host access (http://*/*, https://*/*) + cookies + webRequest enables full cross-site data visibility.
- Privacy policy not scoped to this extension and lacks data-collection/retention disclosures.
- new Function() constructor present; context appears globalThis polyfill but still an eval-class risk.
- 13M installs make this a high-value target if extension or supply chain is ever compromised.
- third_party_silence in privacy policy — no statement on whether data is shared with third parties.
Evidence
- verified_publisher + recognized_org (PayPal) store Verified publisher badge present; developer domain paypal.com resolves; confirmed brand owner.
- broad host permissions + cookies + webRequest manifest cookies & webRequest paired with <all_urls> — ×1.2 multiplier applied; justified-broad discount applied for Shopping.
- privacy policy not scoped to extension api fetched=true, scope_extension=false, data_collection=false → +9.0 privacy; third_party_silence adds +1.0.
- function_constructor in merchantSPBResponders.js crx new Function() use matches globalThis polyfill pattern; +2.5 code quality per debugger_attach/function_constructor rule.
- no CVEs, no bad hosts, no monetization/affiliate hits api cve_findings_raw=[], bad_host_hits=[], monetization_hits=[], affiliate_hits=[] — all clean.
- recently updated, MV3, strict CSP manifest Last updated June 2026 (0 months); MV3; CSP script-src 'self' only — no unsafe-eval/inline.
- operator cluster: no siblings api sibling_count=0 across dev_email, csp_host_set, compound fingerprints.
- no review red flags, no ownership change store review match_count=0; wayback ownership_changed=false.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- cookies high Can read/write cookies across all sites via broad host_permissions.
- webRequest high Observe all network requests across all URLs; paired with <all_urls>.
- scripting medium Programmatic script injection into any page; justified for coupon application.
- http://*/* high Broad host access to all HTTP sites enables wide content-script reach.
- https://*/* high Broad host access to all HTTPS sites; core to Shopping category function.
- storage low Standard local state persistence.
- unlimitedStorage low Allows larger local data store; low direct risk.
- alarms low Periodic background wake; minimal risk.
- offscreen low Off-screen document for DOM tasks; limited surface.
Pillar Scores
Permissions5.10
Reputation2.00
Network2.00
Webstore2.00
Maintenance0.00
Privacy9.00
Code Quality2.50
CVE Exposure0.00
Scoring History
| fsssiedxn88b55a5czan88b55a5czsssiedx | 4.00 | Medium | review | 2026-08-25 |
| sssiedn1545ab70dp727562726963xsx | 3.47 | Low | review | 2026-08-25 |
| sssieddrubricxsx | 3.44 | Low | review | 2026-08-15 |
| v3.6 | 3.14 | Low | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 12:19
Listing SHA
c3ed1437bf2d…
Force block
— not fired
Score recovered
no
Elapsed
—