Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Alitools Shopping Assistant

eenflijjbchafephdplkdmeenekabdfb
Risk Score
4.66
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 400,000
Rating 4.5
Last updated 2026-07-19 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@alitools.io
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own generic policy — no scope, no collection disclosure for this extension. Pillar score 10.
  • cookies + <all_urls> + scripting/webRequest allows full credential and session token harvesting across all sites.
  • Multiple innerHTML DOM-XSS sinks (5 files) paired with new Function() usage elevates XSS escalation risk under <all_urls>.
  • Developer name absent from listing; only email on alitools.io; no disclosed data handling specific to this extension.
  • 12 distinct external JS hosts contacted including beru.ru, mvideo.ru (RU-origin), allegrostatic.com — broad network surface.

Evidence

  • privacy_policy_generic store Privacy URL points to Google's own account policy. scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
  • broad_host_permission manifest <all_urls> host_permission + content_scripts_matches=[<all_urls>] paired with cookies, scripting, webRequest.
  • code_quality_innerhtml_function_constructor crx 5 innerHTML DOM-XSS sinks + 4 new Function() instances across 6 JS files. CSP present → dom_sink scored at +0.5 each but stacks.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true. Discount applies; capped per 0c if monetization hits — none found.
  • developer_name_missing store developer_name is empty string. Email support@alitools.io on resolving domain.
  • external_hosts_diverse crx 12 external JS hosts including beru.ru, www.mvideo.ru (Russian e-commerce), allegrostatic.com. >3 distinct domains.
  • cve_none crx cve_findings_raw is empty. CVE pillar = 0.0.
  • maintenance_recent store last_updated May 18 2026, months_since_update=1. Maintenance pillar = 0.0.

Permissions Breakdown

  • contextMenus low Standard UI integration, low risk.
  • cookies high Can read/write cookies across all sites due to <all_urls> host permission.
  • notifications low Shows desktop notifications; limited harm potential.
  • tabs medium Can read tab URLs and metadata across all sites.
  • webNavigation medium Monitors navigation events across all pages.
  • storage low Local extension storage only.
  • scripting high Programmatic script injection into any page via <all_urls>.
  • alarms low Periodic background scheduling, low risk.
  • webRequest high Can observe all HTTP/S requests across all sites.
  • <all_urls> (host_permission) high Broad host access amplifies cookies, scripting, webRequest risk.

Pillar Scores

Permissions6.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Scoring History

xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.12 Medium review 2026-08-09
%27fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.79 Medium review 2026-08-09
&#x22;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.30 Medium review 2026-08-09
fsssiedxa<sssiedx 4.17 Medium review 2026-08-09
<fsssiedx{ xx psssiedx 4.07 Medium review 2026-08-02
<fsssiedx{$"sssiedx 4.19 Medium review 2026-08-02
<fsssiedxh sssiedx 4.17 Medium review 2026-08-02
<fsssiedxh 4.07 Medium review 2026-08-02
fsssiedx<sssiedx 4.14 Medium review 2026-08-02
fsssiedxw"sssiedx 4.05 Medium review 2026-08-02
sssieddrubricxsx 4.17 Medium review 2026-08-02
v3.6 4.66 Medium review 2026-06-16
v3.4-rev 4.47 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA b1152d3e94fe…
Force block — not fired
Score recovered no
Elapsed 33.6s