Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ali Helper - AliExpress Product Research Tool

lgjchjneebpedgiljdmljfdjmmlabphg
Risk Score
6.34
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Shopping
Installs 3,000
Rating 3.8
Last updated 2023-12-19 (31 months ago)
Manifest version MV3
CSP present ✅ yes
Developer avenger8436@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Massive unpatched CVE stack: 10+ high-severity axios & webpack-dev-server CVEs including SSRF, prototype pollution, exfiltration, and credential leaks.
  • Extension is 31 months stale (zombie) with known-bad bundled library versions — no fix imminent.
  • <all_urls> host permission far exceeds narrow AliExpress content_script scope, creating broad access surface.
  • Developer is free-webmail (Gmail), no verified publisher badge, privacy policy on Google Sites free hosting.
  • new Function() constructor found in background.bundle.js and devtools.bundle.js — dynamic code execution risk.

Evidence

  • CVE-high-severity-axios crx 10+ high-severity axios CVEs: SSRF, prototype pollution, credential leak, header injection — all unfixed at bundled version.
  • CVE-high-severity-webpack-dev-server crx CVE-2018-14732 (high) + 4 moderate webpack-dev-server CVEs: source code exposure, cross-origin leak.
  • zombie-extension store 31 months since last update; >10 high CVEs unfulfilled; MV3 but deeply stale.
  • function_constructor crx new Function() in background.bundle.js and devtools.bundle.js — dynamic code execution from string concatenation.
  • host-permission-mismatch manifest <all_urls> host_permission but content_scripts scoped only to aliexpress.com/item/*.
  • free-webmail-developer store Developer email avenger8436@gmail.com; no verified publisher; privacy policy on free Google Sites hosting.
  • is_featured_by_google store Featured badge present; partial reputation credit applied but does not offset CVE/staleness risk.
  • tail-attack-surface api install_perm_anomaly.tail_attack_surface=true: small install base + high-tier permission = supply-chain risk.

CVE Exposures (28)

CVELibrarySeverity Fixed inSummary
CVE-2025-30359 webpack-dev-server@unknown moderate 5.2.1 webpack-dev-server users' source code may be stolen when they access a malicious
CVE-2026-6402 webpack-dev-server@unknown moderate 5.2.4 webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS
CVE-2025-30360 webpack-dev-server@unknown moderate 5.2.1 webpack-dev-server users' source code may be stolen when they access a malicious
CVE-2018-14732 webpack-dev-server@unknown high 3.1.11 Missing Origin Validation in webpack-dev-server
CVE-2026-9595 webpack-dev-server@unknown moderate 5.2.5 webpack-dev-server vulnerable to HMR WebSocket interception via permissive user
CVE-2025-62718 axios@unknown moderate 1.15.0 Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
CVE-2019-10742 axios@unknown high 0.18.1 Denial of Service in axios
CVE-2026-25639 axios@unknown high 1.13.5 Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
CVE-2020-28168 axios@unknown moderate 0.21.1 Axios vulnerable to Server-Side Request Forgery
CVE-2026-42034 axios@unknown moderate 1.15.1 Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
CVE-2026-42039 axios@unknown moderate 1.15.1 Axios: unbounded recursion in toFormData causes DoS via deeply nested request da
CVE-2026-42035 axios@unknown high 1.15.1 Axios: Header Injection via Prototype Pollution
CVE-2026-44490 axios@unknown moderate 1.16.0 axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in ax
CVE-2021-3749 axios@unknown high 0.21.2 axios Inefficient Regular Expression Complexity vulnerability
CVE-2026-40175 axios@unknown moderate 1.15.0 Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE-2026-44496 axios@unknown high 1.16.0 Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
CVE-2026-44486 axios@unknown high 1.16.0 Axios: Proxy-Authorization header leaks to redirect target when proxy is re-eval
CVE-2025-27152 axios@unknown high 1.8.2 axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute U
CVE-2026-42038 axios@unknown moderate 1.15.1 Axios: no_proxy bypass via IP alias allows SSRF
CVE-2026-44487 axios@unknown high 1.16.0 Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS
CVE-2026-42033 axios@unknown high 1.15.1 Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and
CVE-2026-44492 axios@unknown high 1.16.0 axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowin
CVE-2026-42043 axios@unknown high 1.15.1 Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC
CVE-2026-42036 axios@unknown moderate 1.15.1 Axios: HTTP adapter streamed responses bypass maxContentLength
CVE-2026-42041 axios@unknown moderate 1.15.1 Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus`
CVE-2026-42040 axios@unknown low 1.15.1 Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
CVE-2026-42042 axios@unknown moderate 1.15.1 Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXS
CVE-2020-7746 chart.js@unknown high 2.9.4 Prototype pollution in chart.js

Permissions Breakdown

  • storage low Stores local extension data; minimal risk on its own.
  • unlimitedStorage low Expands storage quota; low standalone risk.
  • downloads medium Can save files to disk; moderate risk for file-based exfil.
  • <all_urls> (host_permission) high Grants content script / request access across all sites despite narrow declared content_scripts.

Pillar Scores

Permissions4.50
Reputation6.50
Network2.00
Webstore2.00
Maintenance8.50
Privacy1.00
Code Quality2.50
CVE Exposure10.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-16 09:03
Listing SHA fbbf835e88d6…
Force block — not fired
Score recovered no
Elapsed