Aliexpress Search by image
jkcacbjiofjgbnaknoojjboeiinempoa
Risk Score
4.18
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Install URL hijack opens searchbyimage.ru on install; uninstall URL sends UTM-tagged beacon — monetization fingerprint.
- Developer email ganes@yandex.ru (free Yandex webmail) with no independently verified business identity.
- Privacy policy confirms data collection AND third-party sharing but no retention period disclosed.
- 13 months since last update (6-12 mo band) with 200K installs increases stale-extension risk.
- No CSP (MV3 default used but host_permissions + external JS hosts increase network surface).
Evidence
- install_url_hijack crx onInstalled opens https://searchbyimage.ru/?i= — third-party install redirect (+2.0 Webstore).
- uninstall_url_hijack crx setUninstallURL to searchbyimage.ru with UTM params — third-party uninstall beacon (+3.0 Webstore).
- developer_email_yandex store ganes@yandex.ru is free-webmail; no verified business; elevated-risk signal (+1.5 Reputation).
- privacy_policy_data_third_party api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- is_featured_by_google store Featured badge present — applies -2.0 Reputation discount.
- months_since_update_13 store Last updated May 2025; 13 months puts this in 6-12mo band (+3.5 Maintenance).
- js_external_hosts crx 5 external hosts: searchbyimage.com, searchbyimage.ru, aliexpress.com, google.com, google.ru.
- no_cve_no_obfuscation crx cve_findings_raw empty; obfuscation_score 0.0; code_findings_raw empty — clean code surface.
Permissions Breakdown
- contextMenus low Adds right-click menu items; low standalone risk.
- host: https://*.searchbyimage.com/* low Scoped to developer-owned search service domain.
- host: https://*.searchbyimage.ru/* low Scoped to developer-owned search service domain.
Pillar Scores
Permissions1.00
Reputation5.50
Network2.00
Webstore6.00
Maintenance6.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.79 | Low | review | 2026-08-09 |
| "fsssiedxa xx psssiedx | 3.54 | Low | review | 2026-08-09 |
| %22fsssiedxa$"sssiedx | 3.68 | Low | review | 2026-08-09 |
| %27fsssiedxa$"sssiedx | 3.54 | Low | review | 2026-08-09 |
| 'fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.52 | Low | review | 2026-08-09 |
| 'fsssiedxa$'sssiedx | 3.58 | Low | review | 2026-08-09 |
| "fsssiedxa'sssiedx | 3.73 | Low | review | 2026-08-09 |
| "fsssiedxa$'sssiedx | 4.30 | Medium | review | 2026-08-09 |
| $"fsssiedxasssiedx | 3.71 | Low | review | 2026-08-09 |
| fsssiedxa$"sssiedx | 3.44 | Low | review | 2026-08-09 |
| <fsssiedxa"sssiedx | 4.03 | Medium | review | 2026-08-01 |
| <fsssiedxa'sssiedx | 4.09 | Medium | review | 2026-08-01 |
| <fsssiedxa"sssiedx | 3.72 | Low | review | 2026-08-01 |
| <fsssiedxa xx psssiedx | 4.03 | Medium | review | 2026-08-01 |
| <fsssiedxa'sssiedx | 2.99 | Low | review | 2026-08-01 |
| <fsssiedxa | 3.17 | Low | review | 2026-08-01 |
| <fsssiedxa$"sssiedx | 4.19 | Medium | review | 2026-08-01 |
| xx pfsssiedxasssiedx | 4.07 | Medium | review | 2026-08-01 |
| xx pfsssiedxa$"sssiedx | 3.71 | Low | review | 2026-08-01 |
| %22fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.27 | Medium | review | 2026-08-01 |
| %22fsssiedxa$'sssiedx | 3.01 | Low | review | 2026-08-01 |
| "fsssiedxa"sssiedx | 4.23 | Medium | review | 2026-08-01 |
| "fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.12 | Medium | review | 2026-08-01 |
| 4.16 | Medium | review | 2026-08-01 | |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.08 | Medium | review | 2026-08-01 |
| <fsssiedxa$'sssiedx | 3.70 | Low | review | 2026-08-01 |
| fsssiedxa<sssiedx | 4.17 | Medium | review | 2026-08-01 |
| sssieddrubricxsx | 3.06 | Low | review | 2026-07-28 |
| v3.6 | 4.18 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA
a2898b3f0e0a…
Force block
— not fired
Score recovered
no
Elapsed
19.8s