Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Amazon URL Shortener

bonkcfmjkpdnieejahndognlbogaikdg
Risk Score
3.88
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Shopping
Installs 6,000
Rating 4.2
Last updated 2026-03-07 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer r7kamura@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses 'Amazon' in name/description; developer is gmail user with no affiliation.
  • Privacy policy is Google's generic account policy — not scoped to this extension at all; admits data collection and third-party sharing.
  • Free-webmail developer (gmail) with no business website; no verified publisher status.
  • Content scripts active on 27 Amazon domains — any future code change could harvest browsing/purchase data at scale.
  • No CSP declared (MV3 default mitigates somewhat, but combined with unscoped privacy policy raises concern).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false, developer_domain=gmail.com
  • generic_privacy_policy store Policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.0
  • free_webmail_developer store developer_email=r7kamura@gmail.com; no business website; not verified publisher
  • featured_by_google store is_featured_by_google=true; provides -2.0 reputation discount but does not override impersonation risk
  • content_scripts_broad manifest content_scripts_matches covers 27 Amazon TLD domains; low permissions otherwise
  • no_csp manifest content_security_policy=null; MV3 default strict-ext CSP applies, partially mitigating
  • clean_code_scan crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[], cve_findings_raw=[]
  • no_threat_intel_hits api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], sibling_count=0

Permissions Breakdown

  • content_scripts: amazon.* medium Scripts injected across 27 Amazon domains; can read/modify page content including product URLs.

Pillar Scores

Permissions1.50
Reputation7.50
Network0.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA f37b7b0929bf…
Force block — not fired
Score recovered no
Elapsed 20.1s