Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shopify Search By Image

gjlbbcimkbncedhofeknicfkhgaocohl
Risk Score
6.44
Risk Level: High
Recommendation: 🚫 BLOCK
Category Shopping
Installs 14
Rating
Last updated 2026-05-12 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer ecomstal.official@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack redirects to saxsos.xyz — classic monetization/tracking shell pattern.
  • Privacy policy admits data collection and third-party sharing without extension-specific scope (D rule: +10.0).
  • Brand impersonation: claims Shopify affiliation; developer is unverified gmail account.
  • Broad <all_urls> host access with no CSP; DOM-XSS sink (innerHTML) compounds risk.
  • Free-webmail dev + no verified publisher + 14 installs + HIGH permission = tail attack surface.

Evidence

  • uninstall_url_hijack crx setUninstallURL targets https://www.saxsos.xyz/p/sorry.html — 3rd-party domain, webstore rule +3.0.
  • privacy_policy_generic_admits_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.0 (rule D).
  • brand_impersonation store brand_mention.is_impersonation=true for Shopify; developer is gmail, confirmed_owner=false → Reputation +2.0.
  • free_webmail_dev store ecomstal.official@gmail.com, no verified publisher, no business website → Reputation floor elevated.
  • small_install_high_perm api 14 installs with <all_urls> host permission — install_perm_anomaly.small_install_high_perm=true → Webstore +1.5.
  • dom_xss_sink_no_csp crx innerHTML user-controlled in result.js; csp_present=false → Code Quality +2.0 (FIX B).
  • js_external_hosts_broad crx 9 external hosts including saxsos.xyz, yandex.com, t.me, wa.me — >3 distinct domains → Network +1.5.
  • install_url_hijack crx onInstalled opens welcome.html (local); install_url_hijack=true noted but target is local, lower severity.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low inherent risk.
  • <all_urls> high Broad host access across all sites; enables content injection on any page.

Pillar Scores

Permissions4.00
Reputation9.00
Network4.00
Webstore10.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 10:38
Listing SHA 52638ed40866…
Force block — not fired
Score recovered no
Elapsed