ショッピングリサーチャー
imcmhieloonofimeilceagabgdnhnlee
Risk Score
4.74
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- jquery@2.1.4 bundles 4 medium CVEs (XSS) with no CSP, amplifying DOM-manipulation risk on 24 marketplace origins.
- Privacy policy hosted on sedo-logi.com (different domain from re-mine.jp), not scoped to this extension; data collection status unclear.
- install_url_hijack flag set true; onInstalled may open third-party URL — verify destination.
- Affiliate hits to Rakuten network (3 domains) confirm monetization shape; category is Shopping so partially expected but warrants review.
- No developer name listed; 13 months since last update on extension with 60K installs increases supply-chain risk window.
Evidence
- CVE exposure crx jquery@2.1.4 has 4 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); all fixed in >=3.4.0.
- No CSP + vulnerable jQuery manifest content_security_policy is null; jquery@<3.5 + no CSP triggers v2 +2.0 code quality and CVE amplifier x1.5.
- Privacy policy off-domain and unscoped store Policy at sedo-logi.com; scope_extension=false, data_collection=false, third_party_silence=true => +9.0 privacy + +1.0.
- Affiliate network hits crx 3 Rakuten affiliate domains in threat_intel.affiliate_hits; category Shopping partially explains, but 2+ distinct domains => +2.5 webstore.
- install_url_hijack crx install_url_hijack=true, target=null. onInstalled opens external URL; destination unconfirmed => +2.0 webstore.
- 12 external JS hosts crx js_external_hosts has 12 entries including wzrd.in, zenorocha.github.io, shopping-researcher.appspot.com => >3 distinct domains.
- Verified publisher store verified_publisher=true; discount capped at -1.0 due to monetization_hits/affiliate hits (v3.5 invariant 0c).
- Maintenance stale store 13 months since update => +6.0 maintenance pillar (6-24mo band).
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.1.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.1.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.1.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.1.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- contextMenus low Adds right-click menu items; low standalone risk.
- storage low Local data persistence only; low risk.
- host_permissions (24 shopping/marketplace origins) medium Content scripts on major JP/US marketplaces; scoped to stated Shopping function.
Pillar Scores
Permissions3.00
Reputation4.50
Network3.50
Webstore5.50
Maintenance6.00
Privacy9.00
Code Quality2.00
CVE Exposure4.50
Scoring History
| v3.6 | 4.74 | Medium | review | 2026-06-16 |
| v3.4-rev | 2.59 | Low | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA
aca64b781a2a…
Force block
— not fired
Score recovered
no
Elapsed
30.1s