Ali Helper - AliExpress Product Research Tool
lgjchjneebpedgiljdmljfdjmmlabphg
Risk Score
6.34
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Massive unpatched CVE stack: 10+ high-severity axios & webpack-dev-server CVEs including SSRF, prototype pollution, exfiltration, and credential leaks.
- Extension is 31 months stale (zombie) with known-bad bundled library versions — no fix imminent.
- <all_urls> host permission far exceeds narrow AliExpress content_script scope, creating broad access surface.
- Developer is free-webmail (Gmail), no verified publisher badge, privacy policy on Google Sites free hosting.
- new Function() constructor found in background.bundle.js and devtools.bundle.js — dynamic code execution risk.
Evidence
- CVE-high-severity-axios crx 10+ high-severity axios CVEs: SSRF, prototype pollution, credential leak, header injection — all unfixed at bundled version.
- CVE-high-severity-webpack-dev-server crx CVE-2018-14732 (high) + 4 moderate webpack-dev-server CVEs: source code exposure, cross-origin leak.
- zombie-extension store 31 months since last update; >10 high CVEs unfulfilled; MV3 but deeply stale.
- function_constructor crx new Function() in background.bundle.js and devtools.bundle.js — dynamic code execution from string concatenation.
- host-permission-mismatch manifest <all_urls> host_permission but content_scripts scoped only to aliexpress.com/item/*.
- free-webmail-developer store Developer email avenger8436@gmail.com; no verified publisher; privacy policy on free Google Sites hosting.
- is_featured_by_google store Featured badge present; partial reputation credit applied but does not offset CVE/staleness risk.
- tail-attack-surface api install_perm_anomaly.tail_attack_surface=true: small install base + high-tier permission = supply-chain risk.
CVE Exposures (28)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2025-30359 | webpack-dev-server@unknown | moderate | 5.2.1 | webpack-dev-server users' source code may be stolen when they access a malicious |
| CVE-2026-6402 | webpack-dev-server@unknown | moderate | 5.2.4 | webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS |
| CVE-2025-30360 | webpack-dev-server@unknown | moderate | 5.2.1 | webpack-dev-server users' source code may be stolen when they access a malicious |
| CVE-2018-14732 | webpack-dev-server@unknown | high | 3.1.11 | Missing Origin Validation in webpack-dev-server |
| CVE-2026-9595 | webpack-dev-server@unknown | moderate | 5.2.5 | webpack-dev-server vulnerable to HMR WebSocket interception via permissive user |
| CVE-2025-62718 | axios@unknown | moderate | 1.15.0 | Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF |
| CVE-2019-10742 | axios@unknown | high | 0.18.1 | Denial of Service in axios |
| CVE-2026-25639 | axios@unknown | high | 1.13.5 | Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig |
| CVE-2020-28168 | axios@unknown | moderate | 0.21.1 | Axios vulnerable to Server-Side Request Forgery |
| CVE-2026-42034 | axios@unknown | moderate | 1.15.1 | Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0 |
| CVE-2026-42039 | axios@unknown | moderate | 1.15.1 | Axios: unbounded recursion in toFormData causes DoS via deeply nested request da |
| CVE-2026-42035 | axios@unknown | high | 1.15.1 | Axios: Header Injection via Prototype Pollution |
| CVE-2026-44490 | axios@unknown | moderate | 1.16.0 | axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in ax |
| CVE-2021-3749 | axios@unknown | high | 0.21.2 | axios Inefficient Regular Expression Complexity vulnerability |
| CVE-2026-40175 | axios@unknown | moderate | 1.15.0 | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain |
| CVE-2026-44496 | axios@unknown | high | 1.16.0 | Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection |
| CVE-2026-44486 | axios@unknown | high | 1.16.0 | Axios: Proxy-Authorization header leaks to redirect target when proxy is re-eval |
| CVE-2025-27152 | axios@unknown | high | 1.8.2 | axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute U |
| CVE-2026-42038 | axios@unknown | moderate | 1.15.1 | Axios: no_proxy bypass via IP alias allows SSRF |
| CVE-2026-44487 | axios@unknown | high | 1.16.0 | Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS |
| CVE-2026-42033 | axios@unknown | high | 1.15.1 | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and |
| CVE-2026-44492 | axios@unknown | high | 1.16.0 | axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowin |
| CVE-2026-42043 | axios@unknown | high | 1.15.1 | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC |
| CVE-2026-42036 | axios@unknown | moderate | 1.15.1 | Axios: HTTP adapter streamed responses bypass maxContentLength |
| CVE-2026-42041 | axios@unknown | moderate | 1.15.1 | Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` |
| CVE-2026-42040 | axios@unknown | low | 1.15.1 | Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams |
| CVE-2026-42042 | axios@unknown | moderate | 1.15.1 | Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXS |
| CVE-2020-7746 | chart.js@unknown | high | 2.9.4 | Prototype pollution in chart.js |
Permissions Breakdown
- storage low Stores local extension data; minimal risk on its own.
- unlimitedStorage low Expands storage quota; low standalone risk.
- downloads medium Can save files to disk; moderate risk for file-based exfil.
- <all_urls> (host_permission) high Grants content script / request access across all sites despite narrow declared content_scripts.
Pillar Scores
Permissions4.50
Reputation6.50
Network2.00
Webstore2.00
Maintenance8.50
Privacy1.00
Code Quality2.50
CVE Exposure10.00
Bookkeeping
Rubric v3.6
Scored at 2026-07-16 09:03
Listing SHA
fbbf835e88d6…
Force block
— not fired
Score recovered
no
Elapsed
—