Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Share-A-Cart for AliExpress

loaconldpakjgijhffiobikhlcdmbikc
Risk Score
3.26
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Shopping
Installs 1,000
Rating 4.0
Last updated 2026-05-19 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@share-a-cart.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • No CSP + 5 innerHTML sinks across multiple JS files: elevated DOM-XSS risk if any external data flows in.
  • cookies permission scoped to AliExpress allows reading session/cart cookies from a major shopping platform.
  • operator cluster has 4 siblings under same dev email — may indicate mass-deployment pattern.
  • Privacy policy discloses data collection AND third-party sharing but lacks retention period.
  • No developer display name listed on store; reduces accountability.

Evidence

  • dom_sink_innerhtml_userctrl x5 crx 5 files contain innerHTML assignments from variables with no CSP; DOM-XSS attack surface present.
  • csp_present=false + MV3 manifest No content_security_policy declared; MV3 so no +2.0 MV2 penalty but sinks are riskier without CSP.
  • cookies + aliexpress host manifest cookies permission paired with https://*.aliexpress.com/* enables reading AliExpress session cookies.
  • operator_cluster siblings=4 store 4 sibling extensions share same dev email fingerprint; +2.5 webstore signal.
  • privacy_policy third_party_sharing=true, retention=false api Policy scoped and acknowledges collection, but no retention period and shares with third parties.
  • developer_name empty store No 'Offered by' display name; reduces identity accountability.
  • js_external_hosts includes retail domains crx External host list includes abercrombie, adidas, academy etc — consistent with multi-retailer cart sharing.
  • cve_findings_raw empty crx No CVEs detected in bundled libraries; react 17.0.2 in use.

Permissions Breakdown

  • alarms low Scheduling only; minimal risk.
  • clipboardWrite medium Can overwrite user clipboard content silently.
  • storage low Local extension data storage.
  • unlimitedStorage low Allows large local data; minor escalation of storage.
  • tabs medium Can read tab URLs and metadata across sessions.
  • cookies high Can read/write cookies; scoped to host_permissions but includes AliExpress.
  • activeTab low Transient access to current tab on user action.
  • scripting medium Can inject scripts into pages matching host_permissions.
  • https://share-a-cart.com/* low Dev-controlled domain; expected for sync/share functionality.
  • https://crtsh.net/* low Certificate transparency lookup; unusual but low risk.
  • https://*.aliexpress.com/* medium Broad access to AliExpress including cart/session cookies.

Pillar Scores

Permissions5.30
Reputation5.50
Network2.00
Webstore5.00
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00

Operator Siblings (4)

Other extensions sharing this developer's compound fingerprint:

Scoring History

v3.6 3.26 Low review 2026-06-16
v3.4-rev 3.76 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA 0b45b2bafae1…
Force block — not fired
Score recovered no
Elapsed 28.3s