AliExpress Deals Countdown - Flash Sale Timer
jmlgkeaofknfmnbpmlmadnfnfajdlehn
Risk Score
5.02
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection AND third-party sharing without scoping to this extension (v3.5 D → +10.0 privacy).
- Uninstall-URL hijack routes users to saxsos.xyz on removal — classic monetization/tracking shell pattern (+3.0 webstore).
- Free-webmail developer (gmail) with no verified business identity; saxsos.xyz is the sole infra domain (+1.5 reputation).
- JS external host saxsos.xyz also serves the privacy policy and uninstall page — single throwaway-looking domain controls all telemetry surface.
- Geo-diversity: JS hosted across 5 countries (CA,GB,PL,SG,US) with no VPN/CDN justification (+1.5 network).
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → saxsos.xyz/p/sorry.html; 3rd-party redirect on removal.
- privacy_policy_scope_mismatch crx Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5-D +10.0.
- free_webmail_developer store Developer email ecomstal.official@gmail.com; no verified business domain; reputation floor ≥7.5.
- js_external_host crx www.saxsos.xyz is only external JS host; same domain as privacy policy and uninstall URL.
- host_geo_diversity api JS host spans 5 countries (CA,GB,PL,SG,US); not a VPN/CDN category extension.
- install_count_very_low store Only 3 installs; brand-new unknown publisher with broad content-script access to AliExpress sessions.
- no_csp crx content_security_policy is null; MV3 default applies but no explicit CSP declared.
- cve_findings crx cve_findings_raw empty; no library CVEs detected.
Permissions Breakdown
- storage low Stores local extension state; no cross-site risk on its own.
- *://*.aliexpress.com/* (and 13 TLD variants) medium Broad content-script injection across all AliExpress TLDs; scoped to stated function.
Pillar Scores
Permissions2.00
Reputation7.50
Network3.50
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 14:50
Listing SHA
e94f21a09759…
Force block
— not fired
Score recovered
no
Elapsed
—