Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Amazon Weight Converter

dfnannaibdndmkienngjahldiofjbkmj
Risk Score
4.66
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 6
Rating
Last updated 2026-01-01 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer 10xprofitio@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: dev is Gmail-only, confirmed_owner=false, uses Amazon brand without authorization.
  • Privacy policy admits data collection + third-party sharing but is NOT scoped to this extension — worst-case privacy posture.
  • Free-webmail developer (Gmail) with no verified business identity; 10xprofit.io domain not validated.
  • innerHTML DOM-XSS sink in content.js with no CSP — any data Amazon pages expose could be misused.
  • install_url_hijack opens welcome.html on install; external JS host app.10xprofit.io raises accountability questions.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; developer_domain=gmail.com; confirmed_owner=false for Amazon brand.
  • privacy_policy_d_clause api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D-clause: score +10.0.
  • free_webmail_developer store Developer email 10xprofitio@gmail.com; no verified publisher badge; no featured badge.
  • dom_xss_sink_no_csp crx innerHTML user-controlled in content.js; csp_present=false raises XSS risk per FIX B.
  • install_url_hijack manifest install_url_hijack=true targeting welcome.html; opens page on install.
  • external_js_host crx js_external_hosts=[app.10xprofit.io]; unverified third-party domain contacts extension.
  • maintenance_stale store months_since_update=7; falls in 3-6 month band (+1.5) or 6-12 band (+3.5); using 7mo → +3.5.
  • very_low_install_count store Only 6 installs; near-zero community validation; tail-attack-surface anomaly noted.

Permissions Breakdown

  • storage low Used to persist user settings; minimal risk.
  • host_permissions: *://*.amazon.*/* medium Content script on all Amazon TLDs; scoped to stated function but broad across 22 domains.

Pillar Scores

Permissions1.50
Reputation7.50
Network0.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:48
Listing SHA 795d677b08f4…
Force block — not fired
Score recovered no
Elapsed