Karma | Online shopping, but better
emalgedpdlghbkikiaeocoblajamonoh
Risk Score
2.92
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- webRequest + broad host access (<all_urls>) enables full request observation across every site visited.
- scripting + broad host access allows arbitrary JS injection on all HTTP/HTTPS pages.
- No CSP on MV3 extension with 8 external JS hosts including tinyurl.com and github.com.
- innerHTML DOM-XSS sink in hermesSDK.js without CSP guard — exploitable if data is attacker-influenced.
- Privacy policy discloses third-party data sharing; shopping extension contacts 8 distinct external domains.
Evidence
- broad_host_permissions manifest host_permissions: http://*/* and https://*/* grant access to every site.
- webRequest_broad manifest webRequest declared with all-URL host permissions — full request observation capability.
- no_csp crx content_security_policy is null; no script-src restriction on MV3 extension.
- external_hosts crx 8 distinct external JS hosts including tinyurl.com, github.com, fe-evas.fih.io, vio.com.
- dom_xss_sink crx innerHTML assignment in js/hermesSDK.js — DOM-XSS risk, amplified by absent CSP.
- verified_publisher_featured store Extension is verified publisher and featured by Google; reputation floored at 2.0.
- privacy_policy_third_party api Policy fetched, scoped, retention disclosed, but third_party_sharing == true adds +1.0 privacy.
- geo_diversity crx JS hosts span 3 countries (CA, IN, US); below threshold of 4 for geo-diversity penalty.
Permissions Breakdown
- tabs medium Can read tab URLs and titles; paired with broad host access increases sensitivity.
- scripting high Programmatic script injection into pages; broad host access makes this near-universal.
- webRequest high Observe all browser requests across all sites; core tracking/monitoring capability.
- storage low Local data persistence only; low standalone risk.
- http://*/* high Broad host access over HTTP for all sites.
- https://*/* high Broad host access over HTTPS for all sites.
Pillar Scores
Permissions5.50
Reputation2.00
Network3.50
Webstore2.00
Maintenance0.00
Privacy1.00
Code Quality0.50
CVE Exposure0.00
Scoring History
| fsssiedxn5fa3f2b4za'n5fa3f2b4zsssiedx | 3.36 | Low | review | 2026-08-30 |
| sssiedn8a5300e8dp727562726963xsx | 2.73 | Low | review | 2026-08-30 |
| v3.6 | 2.92 | Low | allow | 2026-06-16 |
| v3.4-rev | 2.96 | Low | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA
c63f8b58d876…
Force block
— not fired
Score recovered
no
Elapsed
34.7s