DS Amazon Quick View Extended
ilpimgbmpmhfhdaaeepjokoigelkfbee
Risk Score
2.72
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Gmail developer with Amazon brand impersonation — unverified individual operating under major-brand name.
- install_url_hijack: onInstalled opens a third-party URL, classic monetization/tracking vector.
- No CSP on MV3 extension with 5 external JS hosts including personal domain dmitry.artamoshkin.com.
- Content scripts injected on all 22 Amazon TLDs give full DOM read/write on every Amazon page visit.
- Privacy policy discloses third-party data sharing but developer identity is a free-webmail individual.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands=['amazon']; confirmed_owner=false; dev email fromamid@gmail.com.
- install_url_hijack crx install_url_hijack=true; target=null. onInstalled fires to unknown 3rd-party URL.
- free_webmail_developer store Developer email fromamid@gmail.com — free webmail, no verified business identity.
- no_csp crx content_security_policy=null on MV3 extension with 5 external JS hosts.
- external_js_hosts crx 5 external hosts: charts.camelcamelcamel.com, dmitry.artamoshkin.com, graph.keepa.com, keepa.com, www.amazon.com.
- broad_content_scripts manifest Content scripts injected on all 22 amazon.* TLD patterns — full DOM access on every Amazon page.
- privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=true.
- rating_below_threshold store Rating 3.4 — below 4.0; no review red flags detected by automated scan.
Permissions Breakdown
- storage low Local key-value storage only; no cross-origin or user-data exposure.
- host_permissions: *://*.amazon.*/* medium 22 Amazon TLD wildcards; broad but scoped to Amazon. Content-script injection on all Amazon pages.
Pillar Scores
Permissions2.50
Reputation7.50
Network3.50
Webstore5.00
Maintenance0.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA
bb933332318e…
Force block
— not fired
Score recovered
no
Elapsed
19.4s