Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

LogisFlow - Công cụ đặt hàng Trung Quốc

fnkbnfbbpaokkljhhgijlaldocgocmpm
Risk Score
5.52
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 18
Rating
Last updated 2026-08-17 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer mjunhan123@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • cookies permission on Taobao/1688/Tmall enables session token theft from Chinese shopping accounts
  • Free-webmail dev (gmail) with no developer name and no verified publisher — unaccountable identity
  • Privacy policy not scoped to this extension, data_collection field false but third_party_silence true
  • innerHTML DOM-XSS sink in content/product.js with no CSP — XSS if page data is attacker-controlled
  • Small install count (18) with high-tier permissions flags tail-attack-surface risk

Evidence

  • cookies_high_perm_shopping_sites manifest cookies + scripting on *.1688.com, *.taobao.com, *.tmall.com — can read session cookies on major Chinese e-commerce platforms.
  • free_webmail_no_dev_name store developer_email=mjunhan123@gmail.com, developer_name empty, not verified, not featured — reputation floor 7.5.
  • privacy_policy_not_extension_scoped api Policy fetched but scope_extension=false, data_collection=false, third_party_silence=true → Privacy pillar +9.0.
  • dom_xss_sink_no_csp crx innerHTML from variable in content/product.js; CSP absent → FIX B applies, +2.0 code quality.
  • supabase_external_host crx js_external_hosts includes skcanycvlszdshbnrqxd.supabase.co — third-party data backend for extension data.
  • small_install_high_perm api install_perm_anomaly: 18 installs with high-tier permission (cookies) flagged as small_install_high_perm=true.
  • no_csp_mv3 manifest content_security_policy=null; MV3 has strict default but no explicit CSP declared alongside innerHTML sink.
  • cve_findings_empty crx No CVEs detected in bundled libraries; CVE pillar=0.0.

Permissions Breakdown

  • scripting medium Can inject JS into scoped pages (1688, Taobao, Tmall, logisflow.vercel.app).
  • tabs medium Can read tab URLs and metadata; moderate risk for browsing profiling.
  • cookies high Can read/write cookies on scoped Chinese e-commerce sites — session hijack risk.
  • https://*.1688.com/* medium Scoped host access; matches stated function but enables cookie+scripting on shopping site.
  • https://*.taobao.com/* medium Scoped host access; cookies+scripting on Taobao account pages is elevated.
  • https://*.tmall.com/* medium Scoped host access; same risk surface as Taobao.
  • https://logisflow.vercel.app/* low Dev-controlled backend; scoped to own service.

Pillar Scores

Permissions4.00
Reputation7.50
Network2.00
Webstore4.00
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 15:53
Listing SHA e51521ef1c19…
Force block — not fired
Score recovered no
Elapsed