Ebay Cart Exporter
cjadknidmgdfahbflldlhnkdpibhfpfg
Risk Score
4.68
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is a generic freeprivacypolicy.com template not scoped to this extension, yet admits data collection and third-party sharing.
- Brand impersonation: extension references 'eBay' but developer (inboxeen.com) is not a confirmed eBay owner.
- jQuery 3.4.1 bundled with two moderate XSS CVEs (CVE-2020-11022, CVE-2020-11023); not updated to fixed 3.5.0.
- Extension last updated 14 months ago; known-vulnerable jQuery library remains unpatched.
- Host permission covers eBay payment subdomain, exposing checkout/payment flow data to script injection.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; developer domain inboxeen.com is not confirmed eBay owner.
- generic_privacy_policy store Policy on freeprivacypolicy.com: scope_extension=false, data_collection=true, third_party_sharing=true => +10.0 privacy.
- cve_jquery_moderate crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (XSS); fixed_in 3.5.0; 2 medium CVEs.
- stale_extension store months_since_update=14; falls in 12-24mo band (+6.0 maintenance).
- payment_host_permission manifest host_permissions includes https://cart.payments.ebay.com/* — payment subdomain accessible to scripting.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, no external JS hosts; code quality benign.
- threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain resolves, not throwaway.
- low_install_base store Only 86 installs; install_perm_anomaly flags all false; blast radius limited.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- activeTab low Only activates on user-initiated action; no persistent host access.
- scripting medium Can inject JS into pages; scoped to ebay cart host_permissions here.
- https://cart.ebay.com/* medium Narrow eBay cart host; accesses cart data including quantities and payment context.
- https://cart.payments.ebay.com/* medium Payment subdomain; could expose payment flow data during cart export.
Pillar Scores
Permissions2.30
Reputation6.00
Network0.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA
acc994d6f0ce…
Force block
— not fired
Score recovered
no
Elapsed
24.3s