Dopni - Automatic Cashback Service
ekafoahfmdgaeefeeneiijbehnbocbij
Risk Score
6.79
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Abandoned extension (63 months stale, MV2) with broad cookies+*://*/* access — high takeover/abuse risk.
- Privacy policy URL returns fetch error; effectively no policy — max privacy score.
- cookies + *://*/* combo on a cashback extension enables full session-cookie exfiltration across all sites.
- No CSP on MV2 extension with DOM-XSS innerHTML sink in popup.js.
- Only 11 installs with HIGH-tier permissions — tail-attack-surface anomaly flagged.
Evidence
- broad_host_plus_cookies manifest cookies + *://*/* declared together; ×1.2 multiplier applied — can read session tokens on every site.
- maintenance_stale store 63 months since last update (>36mo) — MV2 zombie extension; +10.0 maintenance pillar.
- privacy_policy_fetch_error api privacy_policy_classification.fetched==false (HTTPError); policy URL unreachable — scored +10.0 privacy.
- no_csp_mv2 manifest csp_present==false on MV2 manifest; +2.0 network per v2 calibration fix (b).
- dom_sink_innerhtml crx popup.js: innerHTML assignment from variable; no CSP present → +2.0 code quality (FIX B).
- install_perm_anomaly api 11 installs + HIGH-tier perms: small_install_high_perm=true, tail_attack_surface=true.
- triple_stale_fingerprint store >24mo + MV2 + no CVEs found but still stale; +2.0 webstore triple-stale per v2 fix (c).
- no_verified_publisher store verified_publisher=false, is_featured=false; no reputation discounts applicable.
Permissions Breakdown
- declarativeContent low Allows conditional page-action display; low standalone risk.
- storage low Local key-value storage; low risk.
- tabs medium Access to tab URLs and metadata; moderate sensitivity.
- activeTab medium Temporary access to current page; medium when combined with broad host perms.
- cookies high Can read/write all cookies across all sites — high exfil potential.
- *://*/* high Broad host access; allows content injection and data reads on every site visited.
Pillar Scores
Permissions8.00
Reputation5.00
Network4.00
Webstore4.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:09
Listing SHA
e5259f8ef22c…
Force block
— not fired
Score recovered
no
Elapsed
—