Amazon Keyword Density & SEO Tool
ekomkpgkmieaaekmaldmaljljahehkoi
Risk Score
5.14
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension — highest-risk privacy posture.
- Brand impersonation: extension is Amazon-themed but developer is unverified gmail-account; confirmed_owner=false.
- Uninstall URL hijack to 10xprofit.io/tools — classic monetization/tracking signal on uninstall.
- Free-webmail developer (gmail) with no verified business identity; no publisher badge.
- Geo-diverse JS hosts (CN, FR, IE, US) with 4 countries; no CSP despite MV3 manifest.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands=['amazon']; developer_domain=gmail.com; confirmed_owner=false.
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL targets https://10xprofit.io/tools — 3rd-party monetization/tracking on uninstall.
- privacy_policy_generic_with_data_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — scores +10.0 (D rule).
- free_webmail_developer store Developer email 10xprofitio@gmail.com; no verified publisher; no featured badge.
- geo_diverse_js_hosts crx JS hosts span 4 countries (CN, FR, IE, US); category=Shopping not in exemption list.
- no_csp manifest content_security_policy=null; MV3 so no +2.0 MV2 penalty but DOM risk unmitigated.
- host_permissions_amazon_tlds manifest 21 Amazon TLD host_permissions; content_scripts on 12; matches SEO stated purpose.
- tiny_install_base store Only 22 installs; limited blast radius but reduces trust signal significantly.
Permissions Breakdown
- activeTab low Grants access only to current tab on user action; scoped and low-risk.
- storage low Stores extension state locally; no exfil risk on its own.
- host_permissions: *://*.amazon.*/ medium Broad access across 21 Amazon TLDs; matches stated SEO function but still significant reach.
Pillar Scores
Permissions2.30
Reputation7.00
Network2.50
Webstore6.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:55
Listing SHA
fd142a602e70…
Force block
— not fired
Score recovered
no
Elapsed
—