Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AliExpress Deals Countdown - Flash Sale Timer

jmlgkeaofknfmnbpmlmadnfnfajdlehn
Risk Score
5.02
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 3
Rating
Last updated 2026-05-12 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer ecomstal.official@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection AND third-party sharing without scoping to this extension (v3.5 D → +10.0 privacy).
  • Uninstall-URL hijack routes users to saxsos.xyz on removal — classic monetization/tracking shell pattern (+3.0 webstore).
  • Free-webmail developer (gmail) with no verified business identity; saxsos.xyz is the sole infra domain (+1.5 reputation).
  • JS external host saxsos.xyz also serves the privacy policy and uninstall page — single throwaway-looking domain controls all telemetry surface.
  • Geo-diversity: JS hosted across 5 countries (CA,GB,PL,SG,US) with no VPN/CDN justification (+1.5 network).

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL → saxsos.xyz/p/sorry.html; 3rd-party redirect on removal.
  • privacy_policy_scope_mismatch crx Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5-D +10.0.
  • free_webmail_developer store Developer email ecomstal.official@gmail.com; no verified business domain; reputation floor ≥7.5.
  • js_external_host crx www.saxsos.xyz is only external JS host; same domain as privacy policy and uninstall URL.
  • host_geo_diversity api JS host spans 5 countries (CA,GB,PL,SG,US); not a VPN/CDN category extension.
  • install_count_very_low store Only 3 installs; brand-new unknown publisher with broad content-script access to AliExpress sessions.
  • no_csp crx content_security_policy is null; MV3 default applies but no explicit CSP declared.
  • cve_findings crx cve_findings_raw empty; no library CVEs detected.

Permissions Breakdown

  • storage low Stores local extension state; no cross-site risk on its own.
  • *://*.aliexpress.com/* (and 13 TLD variants) medium Broad content-script injection across all AliExpress TLDs; scoped to stated function.

Pillar Scores

Permissions2.00
Reputation7.50
Network3.50
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 14:50
Listing SHA e94f21a09759…
Force block — not fired
Score recovered no
Elapsed