Alitools Shopping Assistant
eenflijjbchafephdplkdmeenekabdfb
Risk Score
4.66
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own generic policy — no scope, no collection disclosure for this extension. Pillar score 10.
- cookies + <all_urls> + scripting/webRequest allows full credential and session token harvesting across all sites.
- Multiple innerHTML DOM-XSS sinks (5 files) paired with new Function() usage elevates XSS escalation risk under <all_urls>.
- Developer name absent from listing; only email on alitools.io; no disclosed data handling specific to this extension.
- 12 distinct external JS hosts contacted including beru.ru, mvideo.ru (RU-origin), allegrostatic.com — broad network surface.
Evidence
- privacy_policy_generic store Privacy URL points to Google's own account policy. scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
- broad_host_permission manifest <all_urls> host_permission + content_scripts_matches=[<all_urls>] paired with cookies, scripting, webRequest.
- code_quality_innerhtml_function_constructor crx 5 innerHTML DOM-XSS sinks + 4 new Function() instances across 6 JS files. CSP present → dom_sink scored at +0.5 each but stacks.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true. Discount applies; capped per 0c if monetization hits — none found.
- developer_name_missing store developer_name is empty string. Email support@alitools.io on resolving domain.
- external_hosts_diverse crx 12 external JS hosts including beru.ru, www.mvideo.ru (Russian e-commerce), allegrostatic.com. >3 distinct domains.
- cve_none crx cve_findings_raw is empty. CVE pillar = 0.0.
- maintenance_recent store last_updated May 18 2026, months_since_update=1. Maintenance pillar = 0.0.
Permissions Breakdown
- contextMenus low Standard UI integration, low risk.
- cookies high Can read/write cookies across all sites due to <all_urls> host permission.
- notifications low Shows desktop notifications; limited harm potential.
- tabs medium Can read tab URLs and metadata across all sites.
- webNavigation medium Monitors navigation events across all pages.
- storage low Local extension storage only.
- scripting high Programmatic script injection into any page via <all_urls>.
- alarms low Periodic background scheduling, low risk.
- webRequest high Can observe all HTTP/S requests across all sites.
- <all_urls> (host_permission) high Broad host access amplifies cookies, scripting, webRequest risk.
Pillar Scores
Permissions6.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Scoring History
| xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.12 | Medium | review | 2026-08-09 |
| %27fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.79 | Medium | review | 2026-08-09 |
| "fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.30 | Medium | review | 2026-08-09 |
| fsssiedxa<sssiedx | 4.17 | Medium | review | 2026-08-09 |
| <fsssiedx{ xx psssiedx | 4.07 | Medium | review | 2026-08-02 |
| <fsssiedx{$"sssiedx | 4.19 | Medium | review | 2026-08-02 |
| <fsssiedxh sssiedx | 4.17 | Medium | review | 2026-08-02 |
| <fsssiedxh | 4.07 | Medium | review | 2026-08-02 |
| fsssiedx<sssiedx | 4.14 | Medium | review | 2026-08-02 |
| fsssiedxw"sssiedx | 4.05 | Medium | review | 2026-08-02 |
| sssieddrubricxsx | 4.17 | Medium | review | 2026-08-02 |
| v3.6 | 4.66 | Medium | review | 2026-06-16 |
| v3.4-rev | 4.47 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA
b1152d3e94fe…
Force block
— not fired
Score recovered
no
Elapsed
33.6s