Popularity Sort for eBay™
gikmaepdichkplhdildclnphgpiaiibf
Risk Score
4.62
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing (Privacy=10.0).
- jQuery 1.11.1 bundles 3 medium CVEs (XSS); none fixed below 1.11.1; all unpatched in deployed version.
- Brand impersonation: eBay™ trademark used in name/title; developer is not a confirmed eBay owner.
- Content script injected on <all_urls> gives DOM access on every site, amplifying CVE XSS risk.
- Dynamic <script> creation in jQuery combined with no CSP raises script-injection surface.
Evidence
- privacy_policy_generic_google store Privacy URL points to myaccount.google.com policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
- cve_medium_x3_jquery crx jquery@1.11.1 has CVE-2019-11358, CVE-2020-11023, CVE-2015-9251 (all medium). Fixed in 3.5.0; bundled version far below fixed.
- brand_impersonation_ebay store brand_mention.is_impersonation=true; confirmed_owner=false; eBay trademark used in extension name.
- content_scripts_all_urls manifest content_scripts_matches=[<all_urls>]; broad DOM injection on every site the user visits.
- csp_absent_mv3 manifest content_security_policy=null; MV3 provides defaults but no explicit CSP hardening declared.
- script_src_dynamic_jquery crx jQuery JSONP transport creates dynamic <script> elements; combined with CVE-laden version raises XSS risk.
- installs_10k_plus store 40,000 installs; moderate blast radius for any supply-chain or XSS exploit via unpatched jQuery.
- maintenance_3_6mo store Last updated December 7, 2025; 6 months since update → maintenance score 1.5.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.11.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.11.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.11.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Stores extension settings locally; no user data exfiltration risk on its own.
- content_scripts:<all_urls> high Content script injected on all URLs grants broad DOM read/write across every site visited.
Pillar Scores
Permissions2.50
Reputation6.00
Network0.00
Webstore3.00
Maintenance1.50
Privacy10.00
Code Quality3.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA
d50c80d1f1e4…
Force block
— not fired
Score recovered
no
Elapsed
26.6s