Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Titans Quick View - Amazon Niche Finder

eefljgmhgaidffapnppcmmafobefjece
Risk Score
3.58
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Shopping
Installs 70,000
Rating 4.1
Last updated 2026-04-19 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer selfpublishingtitans@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Developer uses free Gmail address with no registered business name; brand_mention flags Amazon impersonation.
  • Bundled jQuery 3.3.1 has 3 medium CVEs (XSS); not updated to fixed version 3.5.0+.
  • Multiple innerHTML DOM-XSS sinks in content scripts running on Amazon pages could be exploited via page data.
  • Broad *://*/* host_permissions beyond stated Amazon-only use case expands attack surface unnecessarily.
  • Install URL hijacks to selfpublishingtitans.com on every install; opens 3rd-party URL (onInstalled redirect).

Evidence

  • free_webmail_dev store Developer email selfpublishingtitans@gmail.com is free webmail; no verified business name listed.
  • brand_impersonation store brand_mention.is_impersonation=true; 'Amazon' mentioned in title/description; confirmed_owner=false.
  • cve_jquery_3.3.1 crx 3 medium CVEs in bundled jquery@3.3.1 (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed in 3.5.0.
  • dom_xss_sinks crx 3 innerHTML assignments from variables in content scripts on amazon.com pages; potential DOM-XSS.
  • broad_host_permissions manifest host_permissions includes *://*/* despite content_scripts limited to Amazon domains.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens https://selfpublishingtitans.com/extension/welcome.
  • verified_publisher store verified_publisher=true; discount capped because developer_domain_info is null (unresolvable).
  • privacy_policy_third_party api Privacy policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=true.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Local data persistence; standard for extension settings.
  • background low Persistent service worker; needed for async API calls.
  • activeTab low Access to current tab only; lower risk than broad host perms.
  • *://*/* high Broad host permission covering all URLs; content_scripts mostly scoped to Amazon but host_permissions is unbounded.

Pillar Scores

Permissions5.20
Reputation6.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA 06ba76176898…
Force block — not fired
Score recovered no
Elapsed 30.6s