Shopify Product Info by OptimCommerce
hgdnbhdgboglidilhoipggepjlmmmaae
Risk Score
4.37
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetch failed (HTTPError); policy adequacy cannot be confirmed, scored as unfetched.
- Brand impersonation: mentions 'Shopify' but developer is unverified gmail user with no confirmed ownership.
- Content script declared on https://*/* runs on all HTTPS sites, far broader than Shopify-only stated function.
- Developer uses free webmail (gmail) with no developer name listed; identity unverifiable.
- DOM-XSS sink (innerHTML) with no CSP present; stored/reflected data from page could be unsafe.
Evidence
- privacy_policy_fetch_failed api Privacy policy URL returned HTTPError; fetched==false → scored +10.0 on privacy pillar.
- brand_impersonation store brand_mention.is_impersonation==true for 'shopify'; developer is gmail user, confirmed_owner==false.
- broad_content_script manifest content_scripts_matches=['https://*/*'] — all HTTPS sites, but stated purpose is Shopify only.
- free_webmail_no_dev_name store developer_email=hovomk@gmail.com; developer_name is empty; identity unverifiable.
- dom_xss_sink_no_csp crx innerHTML assigned from variable in popup.js; csp_present==false increases XSS risk.
- verified_publisher_featured store verified_publisher==true AND is_featured_by_google==true; partially mitigates reputation risk.
- maintenance_stale store months_since_update=15; falls in 12-24mo band → +6.0 maintenance score.
- no_bad_hosts_no_cves crx bad_host_hits, affiliate_hits, monetization_hits all empty; cve_findings_raw empty.
Permissions Breakdown
- activeTab low Grants access only to the currently active tab on user action; low passive risk.
- scripting medium Allows script injection into pages; paired with activeTab limits scope but still enables DOM manipulation.
- content_scripts https://*/* medium Content script runs on all HTTPS pages, broad reach beyond stated Shopify-only purpose.
Pillar Scores
Permissions2.30
Reputation5.50
Network0.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA
e19f43588db9…
Force block
— not fired
Score recovered
no
Elapsed
21.9s