LogisFlow - Công cụ đặt hàng Trung Quốc
fnkbnfbbpaokkljhhgijlaldocgocmpm
Risk Score
5.52
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies permission on Taobao/1688/Tmall enables session token theft from Chinese shopping accounts
- Free-webmail dev (gmail) with no developer name and no verified publisher — unaccountable identity
- Privacy policy not scoped to this extension, data_collection field false but third_party_silence true
- innerHTML DOM-XSS sink in content/product.js with no CSP — XSS if page data is attacker-controlled
- Small install count (18) with high-tier permissions flags tail-attack-surface risk
Evidence
- cookies_high_perm_shopping_sites manifest cookies + scripting on *.1688.com, *.taobao.com, *.tmall.com — can read session cookies on major Chinese e-commerce platforms.
- free_webmail_no_dev_name store developer_email=mjunhan123@gmail.com, developer_name empty, not verified, not featured — reputation floor 7.5.
- privacy_policy_not_extension_scoped api Policy fetched but scope_extension=false, data_collection=false, third_party_silence=true → Privacy pillar +9.0.
- dom_xss_sink_no_csp crx innerHTML from variable in content/product.js; CSP absent → FIX B applies, +2.0 code quality.
- supabase_external_host crx js_external_hosts includes skcanycvlszdshbnrqxd.supabase.co — third-party data backend for extension data.
- small_install_high_perm api install_perm_anomaly: 18 installs with high-tier permission (cookies) flagged as small_install_high_perm=true.
- no_csp_mv3 manifest content_security_policy=null; MV3 has strict default but no explicit CSP declared alongside innerHTML sink.
- cve_findings_empty crx No CVEs detected in bundled libraries; CVE pillar=0.0.
Permissions Breakdown
- scripting medium Can inject JS into scoped pages (1688, Taobao, Tmall, logisflow.vercel.app).
- tabs medium Can read tab URLs and metadata; moderate risk for browsing profiling.
- cookies high Can read/write cookies on scoped Chinese e-commerce sites — session hijack risk.
- https://*.1688.com/* medium Scoped host access; matches stated function but enables cookie+scripting on shopping site.
- https://*.taobao.com/* medium Scoped host access; cookies+scripting on Taobao account pages is elevated.
- https://*.tmall.com/* medium Scoped host access; same risk surface as Taobao.
- https://logisflow.vercel.app/* low Dev-controlled backend; scoped to own service.
Pillar Scores
Permissions4.00
Reputation7.50
Network2.00
Webstore4.00
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 15:53
Listing SHA
e51521ef1c19…
Force block
— not fired
Score recovered
no
Elapsed
—