Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shopify App Detector by ShopScan

clmnbgdajeklmehpgbkhflfdcpkepdij
Risk Score
4.52
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 5,000
Rating 4.8
Last updated 2026-04-21 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer sakinur@devluxx.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Shopify brand impersonation: extension name/description references Shopify but developer is unaffiliated (devluxx.com).
  • Privacy policy fetched but scope_extension==false and admits data_collection+third_party_sharing — worst-case D rule applies (+10.0 privacy).
  • Install URL hijack: onInstalled opens https://www.shopscan.app/post-install.php (3rd-party redirect).
  • Uninstall URL hijack to https://www.shopscan.app/pages/uninstall and external host cutt.ly (link shortener) in js_external_hosts.
  • No CSP (MV3) and DOM-XSS innerHTML sink writing app-fetched data; cutt.ly link shortener contact raises exfil/redirect concern.

Evidence

  • brand_impersonation store brand_mention.is_impersonation==true; Shopify mentioned but confirmed_owner==false; developer domain is devluxx.com.
  • privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic policy admitting sharing, no extension scope.
  • install_url_hijack crx onInstalled opens https://www.shopscan.app/post-install.php — 3rd-party URL hijack confirmed.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL points to https://www.shopscan.app/pages/uninstall — 3rd-party uninstall redirect.
  • external_host_cutt_ly crx js_external_hosts includes cutt.ly (link shortener) — opaque redirect destination, potential tracking/exfil vector.
  • dom_xss_sink crx popup/popup.js assigns innerHTML from variable appsHTML; no CSP present — DOM-XSS risk if data is attacker-influenced.
  • no_developer_name store developer_name is empty string; identity relies solely on email sakinur@devluxx.com.
  • verified_publisher store verified_publisher==true; partial trust credit applied but capped due to monetization-shape signals (install/uninstall hijack).

Permissions Breakdown

  • activeTab medium Grants access to current tab content on user action; limited scope but enables page inspection.

Pillar Scores

Permissions1.50
Reputation5.50
Network2.00
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA 227320f96282…
Force block — not fired
Score recovered no
Elapsed 22.7s