Search by Image & Price Tracker for eBay
iifbdohpebbkdjakbkiebapfifndlgah
Risk Score
5.67
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies + <all_urls> + scripting: full cookie-read capability across every site visited.
- Brand impersonation: extension claims eBay affiliation but developer is unverified third-party (aiprice.com).
- Privacy policy admits third-party data sharing without scoping to this extension (D-clause: +10.0).
- Dynamic script injection (script_src_dynamic) and new Function() constructor present; no CSP to constrain.
- No developer name listed; eBay brand mention with confirmed_owner=false increases social-engineering risk.
Evidence
- broad_host_access_with_cookies_scripting manifest <all_urls> paired with cookies+scripting = full session-hijack surface on every site.
- brand_impersonation store brand_mention.is_impersonation=true for 'ebay'; confirmed_owner=false; not verified publisher for eBay.
- privacy_policy_admits_third_party_sharing_without_extension_scope api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.0.
- script_src_dynamic crx inject-script.js dynamically creates <script> elements; no CSP to restrict source.
- function_constructor crx new Function() used in vendor bundle; code-execution risk from string input.
- no_csp manifest csp_present=false on MV3; dom_sink_innerhtml_userctrl elevated to +2.0 per FIX B.
- js_external_hosts_count crx 6 distinct external hosts (api-cn.aiprice.com, api.aiprice.com, github.com, index, t, www).
- no_developer_name store developer_name is empty string; combined with brand impersonation raises reputation risk.
Permissions Breakdown
- activeTab low Scoped to user-initiated action; limited blast radius.
- alarms low Scheduling only; no direct data access.
- contextMenus low UI surface only; no data exfil on its own.
- cookies high Can read/write cookies across all URLs given <all_urls> host permission.
- declarativeNetRequest medium Can redirect/block network requests; combined with broad hosts elevates risk.
- declarativeNetRequestFeedback medium Can observe which rules matched; sensitive for traffic analysis.
- notifications low User-visible notifications; low intrinsic risk.
- scripting high Programmatic script injection into any page via <all_urls>.
- storage low Local extension storage; no direct network exfil.
- <all_urls> / http://*/* / https://*/* (host_permissions) high Broad host access amplifies cookies+scripting to full-browser reach.
Pillar Scores
Permissions7.50
Reputation5.50
Network4.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Scoring History
| fsssiedxn426f15b9za xx pn426f15b9zsssiedx | 5.78 | Medium | review | 2026-08-27 |
| sssiednf8b44099dp727562726963xsx | 5.33 | Medium | review | 2026-08-27 |
| <fsssiedxa'sssiedx | 5.94 | Medium | review | 2026-08-24 |
| <fsssiedxa"sssiedx | 4.21 | Medium | review | 2026-08-22 |
| <fsssiedxa"sssiedx | 3.98 | Low | review | 2026-08-22 |
| <fsssiedxa xx psssiedx | 5.13 | Medium | review | 2026-08-22 |
| <fsssiedxa | 5.71 | Medium | review | 2026-08-22 |
| <fsssiedxa$'sssiedx | 5.58 | Medium | review | 2026-08-22 |
| <fsssiedxa'sssiedx | 5.28 | Medium | review | 2026-08-22 |
| <fsssiedxa$"sssiedx | 5.63 | Medium | review | 2026-08-22 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 5.92 | Medium | review | 2026-08-09 |
| fsssiedxa<sssiedx | 5.65 | Medium | review | 2026-08-09 |
| fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.52 | Medium | review | 2026-08-09 |
| sssieddrubricxsx | 5.34 | Medium | review | 2026-08-09 |
| v3.6 | 5.67 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA
561766d59ca7…
Force block
— not fired
Score recovered
no
Elapsed
31.0s