Rakuten: Get Cash Back For Shopping
chhjbpecpncaggjpdakmflnfcopglcmi
Risk Score
3.68
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is generic corporate policy (scope_extension=false) admitting data collection and third-party sharing — worst-case privacy score triggered.
- cookies + <all_urls> + webRequest combination allows broad sitewide cookie read/write and request interception.
- scripting + <all_urls> enables arbitrary JS injection on every visited page.
- No CSP present (MV3 provides some default protection but no explicit scope restriction).
- new Function() constructor in bg.js enables dynamic code execution; low obfuscation but warrants review.
Evidence
- verified_publisher + featured store Rakuten is a verified publisher with Google Featured badge; reputation floored at 2.0.
- privacy_policy_scope_mismatch api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
- cookies + <all_urls> manifest HIGH permission pair; ×1.2 amplifier applied on permissions pillar.
- function_constructor in bg.js crx new Function() found; +2.5 code quality per debugger_attach/function_constructor rule.
- 7 external JS hosts crx button.rrcbsn.com, capture.ecbsn.com, cas.rrcbsn.com, search.ecbsn.com + app stores contacted.
- no bad_host_hits / affiliate_hits / monetization_hits api Threat intel clean; no ad-tech or affiliate network hits detected.
- 3M installs, rating 4.9, zero review red flags store High install count with strong rating and no malware/redirect complaints in reviews.
- justified-broad-permission discount applied manifest Shopping/cashback category matches broad host access; -1.5 discount on permissions pillar.
Permissions Breakdown
- tabs medium Can read tab URLs and titles across all navigation events.
- webNavigation medium Observes all navigation events; needed for cashback trigger detection.
- webRequest high Intercepts all HTTP requests across all URLs — high surveillance capability.
- storage low Stores extension state locally; standard low risk.
- cookies high Combined with <all_urls> allows reading/writing cookies sitewide — ×1.2 amplifier applies.
- alarms low Schedules background tasks; low standalone risk.
- scripting high Programmatic script injection into pages; paired with <all_urls> is broad capability.
- <all_urls> (host_permission) high Grants access to every origin; justified by cashback category but amplifies cookies+webRequest.
Pillar Scores
Permissions4.50
Reputation2.00
Network3.50
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Scoring History
| xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.51 | Low | review | 2026-08-09 |
| %22fsssiedxa sssiedx | 4.12 | Medium | review | 2026-08-09 |
| %27fsssiedxa$'sssiedx | 4.02 | Medium | review | 2026-08-09 |
| 4.08 | Medium | review | 2026-08-09 | |
| $"fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.78 | Low | review | 2026-08-09 |
| fsssiedxa$"sssiedx | 3.73 | Low | review | 2026-08-09 |
| <fsssiedxi xx psssiedx | 3.61 | Low | review | 2026-08-08 |
| <fsssiedxi$"sssiedx | 4.27 | Medium | review | 2026-08-08 |
| <fsssiedxa xx psssiedx | 3.69 | Low | review | 2026-08-03 |
| <fsssiedxa"sssiedx | 3.74 | Low | review | 2026-08-03 |
| <fsssiedxifdsaxax><!--></ScRiPt>asddsssiedx | 2.81 | Low | review | 2026-08-03 |
| <fsssiedxi'sssiedx | 4.34 | Medium | review | 2026-08-03 |
| fsssiedx<sssiedx | 2.59 | Low | review | 2026-08-03 |
| <fsssiedxa"sssiedx | 3.77 | Low | review | 2026-08-02 |
| <fsssiedxa$'sssiedx | 3.58 | Low | review | 2026-08-02 |
| <fsssiedxa'sssiedx | 3.67 | Low | review | 2026-08-02 |
| <fsssiedxa$"sssiedx | 3.68 | Low | review | 2026-08-02 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.69 | Low | review | 2026-08-02 |
| <fsssiedxa'sssiedx | 4.07 | Medium | review | 2026-08-02 |
| fsssiedxa<sssiedx | 3.39 | Low | review | 2026-08-02 |
| sssieddrubricxsx | 3.99 | Low | review | 2026-07-31 |
| v3.6 | 3.68 | Low | review | 2026-06-16 |
| v3.4-rev | 4.67 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA
b27491502a1c…
Force block
— not fired
Score recovered
no
Elapsed
26.8s