Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Search by Image & Price Tracker for eBay

iifbdohpebbkdjakbkiebapfifndlgah
Risk Score
5.67
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PriceTracker
Installs 6,000
Rating 4.9
Last updated 2026-06-17 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer hui.song@aiprice.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + <all_urls> + scripting: full cookie-read capability across every site visited.
  • Brand impersonation: extension claims eBay affiliation but developer is unverified third-party (aiprice.com).
  • Privacy policy admits third-party data sharing without scoping to this extension (D-clause: +10.0).
  • Dynamic script injection (script_src_dynamic) and new Function() constructor present; no CSP to constrain.
  • No developer name listed; eBay brand mention with confirmed_owner=false increases social-engineering risk.

Evidence

  • broad_host_access_with_cookies_scripting manifest <all_urls> paired with cookies+scripting = full session-hijack surface on every site.
  • brand_impersonation store brand_mention.is_impersonation=true for 'ebay'; confirmed_owner=false; not verified publisher for eBay.
  • privacy_policy_admits_third_party_sharing_without_extension_scope api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.0.
  • script_src_dynamic crx inject-script.js dynamically creates <script> elements; no CSP to restrict source.
  • function_constructor crx new Function() used in vendor bundle; code-execution risk from string input.
  • no_csp manifest csp_present=false on MV3; dom_sink_innerhtml_userctrl elevated to +2.0 per FIX B.
  • js_external_hosts_count crx 6 distinct external hosts (api-cn.aiprice.com, api.aiprice.com, github.com, index, t, www).
  • no_developer_name store developer_name is empty string; combined with brand impersonation raises reputation risk.

Permissions Breakdown

  • activeTab low Scoped to user-initiated action; limited blast radius.
  • alarms low Scheduling only; no direct data access.
  • contextMenus low UI surface only; no data exfil on its own.
  • cookies high Can read/write cookies across all URLs given <all_urls> host permission.
  • declarativeNetRequest medium Can redirect/block network requests; combined with broad hosts elevates risk.
  • declarativeNetRequestFeedback medium Can observe which rules matched; sensitive for traffic analysis.
  • notifications low User-visible notifications; low intrinsic risk.
  • scripting high Programmatic script injection into any page via <all_urls>.
  • storage low Local extension storage; no direct network exfil.
  • <all_urls> / http://*/* / https://*/* (host_permissions) high Broad host access amplifies cookies+scripting to full-browser reach.

Pillar Scores

Permissions7.50
Reputation5.50
Network4.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Scoring History

fsssiedxn426f15b9za xx pn426f15b9zsssiedx 5.78 Medium review 2026-08-27
sssiednf8b44099dp727562726963xsx 5.33 Medium review 2026-08-27
<fsssiedxa&#x27;sssiedx 5.94 Medium review 2026-08-24
<fsssiedxa"sssiedx 4.21 Medium review 2026-08-22
<fsssiedxa&#x22;sssiedx 3.98 Low review 2026-08-22
<fsssiedxa xx psssiedx 5.13 Medium review 2026-08-22
<fsssiedxa 5.71 Medium review 2026-08-22
<fsssiedxa$'sssiedx 5.58 Medium review 2026-08-22
<fsssiedxa'sssiedx 5.28 Medium review 2026-08-22
<fsssiedxa$"sssiedx 5.63 Medium review 2026-08-22
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 5.92 Medium review 2026-08-09
fsssiedxa<sssiedx 5.65 Medium review 2026-08-09
fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.52 Medium review 2026-08-09
sssieddrubricxsx 5.34 Medium review 2026-08-09
v3.6 5.67 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA 561766d59ca7…
Force block — not fired
Score recovered no
Elapsed 31.0s