AnyGo — Find Cheaper Agoda Prices
eicepfcebmhdgligechehpcjbakfjcco
Risk Score
3.12
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- cookies_getall_post in interceptor.js: reads ALL cookies (incl. HttpOnly) and sends outbound — credential exfil risk.
- webRequest permission allows interception of agoda.com traffic; combined with cookie access raises capability concern.
- No CSP declared (MV3 default applies but csp_present=false): dom_sink_innerhtml_userctrl elevates XSS risk.
- Very low install count (13) with HIGH-tier permission flagged as small_install_high_perm anomaly.
- Backend at anygo-production.up.railway.app (ephemeral hosting) — ownership/continuity risk.
Evidence
- cookies_getall_post crx interceptor.js calls chrome.cookies.getAll() and posts outbound — matches credential exfil pattern.
- dom_sink_innerhtml_userctrl crx content.js assigns innerHTML from variable without sanitization; no CSP to mitigate XSS.
- webRequest HIGH permission manifest webRequest declared; scoped to agoda.com host but still allows request observation/interception.
- small_install_high_perm anomaly store Only 13 installs with high-tier permission (webRequest + cookies access pattern).
- ephemeral backend host crx anygo-production.up.railway.app is a Railway PaaS subdomain — not a stable dev-controlled domain.
- privacy policy classification api Policy fetched; scoped, data_collection=true, retention=true, third_party_sharing=true. Score +1.0.
- no verified publisher / featured badge store Unverified publisher; no Google featured badge; 0 ratings; reputation starts at 5.0.
- no CVEs detected crx cve_findings_raw is empty; no bundled vulnerable JS libraries detected.
Permissions Breakdown
- storage low Standard local data persistence; low risk.
- webRequest high Can observe/intercept network requests; high capability even scoped to agoda.com.
- https://www.agoda.com/* medium Host access scoped to single domain; matches stated price-checking function.
Pillar Scores
Permissions4.00
Reputation5.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy1.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 11:46
Listing SHA
c269e6f2b7ff…
Force block
— not fired
Score recovered
no
Elapsed
—