Shopify App Detector by ShopScan
clmnbgdajeklmehpgbkhflfdcpkepdij
Risk Score
4.52
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Shopify brand impersonation: extension name/description references Shopify but developer is unaffiliated (devluxx.com).
- Privacy policy fetched but scope_extension==false and admits data_collection+third_party_sharing — worst-case D rule applies (+10.0 privacy).
- Install URL hijack: onInstalled opens https://www.shopscan.app/post-install.php (3rd-party redirect).
- Uninstall URL hijack to https://www.shopscan.app/pages/uninstall and external host cutt.ly (link shortener) in js_external_hosts.
- No CSP (MV3) and DOM-XSS innerHTML sink writing app-fetched data; cutt.ly link shortener contact raises exfil/redirect concern.
Evidence
- brand_impersonation store brand_mention.is_impersonation==true; Shopify mentioned but confirmed_owner==false; developer domain is devluxx.com.
- privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic policy admitting sharing, no extension scope.
- install_url_hijack crx onInstalled opens https://www.shopscan.app/post-install.php — 3rd-party URL hijack confirmed.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL points to https://www.shopscan.app/pages/uninstall — 3rd-party uninstall redirect.
- external_host_cutt_ly crx js_external_hosts includes cutt.ly (link shortener) — opaque redirect destination, potential tracking/exfil vector.
- dom_xss_sink crx popup/popup.js assigns innerHTML from variable appsHTML; no CSP present — DOM-XSS risk if data is attacker-influenced.
- no_developer_name store developer_name is empty string; identity relies solely on email sakinur@devluxx.com.
- verified_publisher store verified_publisher==true; partial trust credit applied but capped due to monetization-shape signals (install/uninstall hijack).
Permissions Breakdown
- activeTab medium Grants access to current tab content on user action; limited scope but enables page inspection.
Pillar Scores
Permissions1.50
Reputation5.50
Network2.00
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA
227320f96282…
Force block
— not fired
Score recovered
no
Elapsed
22.7s