Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ebay Cart Exporter

cjadknidmgdfahbflldlhnkdpibhfpfg
Risk Score
4.68
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 86
Rating 5.0
Last updated 2025-04-15 (14 months ago)
Manifest version MV3
CSP present ✅ yes
Developer extension@inboxeen.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is a generic freeprivacypolicy.com template not scoped to this extension, yet admits data collection and third-party sharing.
  • Brand impersonation: extension references 'eBay' but developer (inboxeen.com) is not a confirmed eBay owner.
  • jQuery 3.4.1 bundled with two moderate XSS CVEs (CVE-2020-11022, CVE-2020-11023); not updated to fixed 3.5.0.
  • Extension last updated 14 months ago; known-vulnerable jQuery library remains unpatched.
  • Host permission covers eBay payment subdomain, exposing checkout/payment flow data to script injection.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; developer domain inboxeen.com is not confirmed eBay owner.
  • generic_privacy_policy store Policy on freeprivacypolicy.com: scope_extension=false, data_collection=true, third_party_sharing=true => +10.0 privacy.
  • cve_jquery_moderate crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (XSS); fixed_in 3.5.0; 2 medium CVEs.
  • stale_extension store months_since_update=14; falls in 12-24mo band (+6.0 maintenance).
  • payment_host_permission manifest host_permissions includes https://cart.payments.ebay.com/* — payment subdomain accessible to scripting.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, no external JS hosts; code quality benign.
  • threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain resolves, not throwaway.
  • low_install_base store Only 86 installs; install_perm_anomaly flags all false; blast radius limited.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • activeTab low Only activates on user-initiated action; no persistent host access.
  • scripting medium Can inject JS into pages; scoped to ebay cart host_permissions here.
  • https://cart.ebay.com/* medium Narrow eBay cart host; accesses cart data including quantities and payment context.
  • https://cart.payments.ebay.com/* medium Payment subdomain; could expose payment flow data during cart export.

Pillar Scores

Permissions2.30
Reputation6.00
Network0.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA acc994d6f0ce…
Force block — not fired
Score recovered no
Elapsed 24.3s