Titans Quick View - Amazon Niche Finder
eefljgmhgaidffapnppcmmafobefjece
Risk Score
3.58
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Developer uses free Gmail address with no registered business name; brand_mention flags Amazon impersonation.
- Bundled jQuery 3.3.1 has 3 medium CVEs (XSS); not updated to fixed version 3.5.0+.
- Multiple innerHTML DOM-XSS sinks in content scripts running on Amazon pages could be exploited via page data.
- Broad *://*/* host_permissions beyond stated Amazon-only use case expands attack surface unnecessarily.
- Install URL hijacks to selfpublishingtitans.com on every install; opens 3rd-party URL (onInstalled redirect).
Evidence
- free_webmail_dev store Developer email selfpublishingtitans@gmail.com is free webmail; no verified business name listed.
- brand_impersonation store brand_mention.is_impersonation=true; 'Amazon' mentioned in title/description; confirmed_owner=false.
- cve_jquery_3.3.1 crx 3 medium CVEs in bundled jquery@3.3.1 (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed in 3.5.0.
- dom_xss_sinks crx 3 innerHTML assignments from variables in content scripts on amazon.com pages; potential DOM-XSS.
- broad_host_permissions manifest host_permissions includes *://*/* despite content_scripts limited to Amazon domains.
- install_url_hijack crx install_url_hijack=true; onInstalled opens https://selfpublishingtitans.com/extension/welcome.
- verified_publisher store verified_publisher=true; discount capped because developer_domain_info is null (unresolvable).
- privacy_policy_third_party api Privacy policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=true.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Local data persistence; standard for extension settings.
- background low Persistent service worker; needed for async API calls.
- activeTab low Access to current tab only; lower risk than broad host perms.
- *://*/* high Broad host permission covering all URLs; content_scripts mostly scoped to Amazon but host_permissions is unbounded.
Pillar Scores
Permissions5.20
Reputation6.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA
06ba76176898…
Force block
— not fired
Score recovered
no
Elapsed
30.6s