Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AnyGo — Find Cheaper Agoda Prices

eicepfcebmhdgligechehpcjbakfjcco
Risk Score
3.12
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category PriceTracker
Installs 13
Rating
Last updated 2026-07-30 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer hello@getanygo.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies_getall_post in interceptor.js: reads ALL cookies (incl. HttpOnly) and sends outbound — credential exfil risk.
  • webRequest permission allows interception of agoda.com traffic; combined with cookie access raises capability concern.
  • No CSP declared (MV3 default applies but csp_present=false): dom_sink_innerhtml_userctrl elevates XSS risk.
  • Very low install count (13) with HIGH-tier permission flagged as small_install_high_perm anomaly.
  • Backend at anygo-production.up.railway.app (ephemeral hosting) — ownership/continuity risk.

Evidence

  • cookies_getall_post crx interceptor.js calls chrome.cookies.getAll() and posts outbound — matches credential exfil pattern.
  • dom_sink_innerhtml_userctrl crx content.js assigns innerHTML from variable without sanitization; no CSP to mitigate XSS.
  • webRequest HIGH permission manifest webRequest declared; scoped to agoda.com host but still allows request observation/interception.
  • small_install_high_perm anomaly store Only 13 installs with high-tier permission (webRequest + cookies access pattern).
  • ephemeral backend host crx anygo-production.up.railway.app is a Railway PaaS subdomain — not a stable dev-controlled domain.
  • privacy policy classification api Policy fetched; scoped, data_collection=true, retention=true, third_party_sharing=true. Score +1.0.
  • no verified publisher / featured badge store Unverified publisher; no Google featured badge; 0 ratings; reputation starts at 5.0.
  • no CVEs detected crx cve_findings_raw is empty; no bundled vulnerable JS libraries detected.

Permissions Breakdown

  • storage low Standard local data persistence; low risk.
  • webRequest high Can observe/intercept network requests; high capability even scoped to agoda.com.
  • https://www.agoda.com/* medium Host access scoped to single domain; matches stated price-checking function.

Pillar Scores

Permissions4.00
Reputation5.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy1.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 11:46
Listing SHA c269e6f2b7ff…
Force block — not fired
Score recovered no
Elapsed