Share-A-Cart for AliExpress
loaconldpakjgijhffiobikhlcdmbikc
Risk Score
3.26
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- No CSP + 5 innerHTML sinks across multiple JS files: elevated DOM-XSS risk if any external data flows in.
- cookies permission scoped to AliExpress allows reading session/cart cookies from a major shopping platform.
- operator cluster has 4 siblings under same dev email — may indicate mass-deployment pattern.
- Privacy policy discloses data collection AND third-party sharing but lacks retention period.
- No developer display name listed on store; reduces accountability.
Evidence
- dom_sink_innerhtml_userctrl x5 crx 5 files contain innerHTML assignments from variables with no CSP; DOM-XSS attack surface present.
- csp_present=false + MV3 manifest No content_security_policy declared; MV3 so no +2.0 MV2 penalty but sinks are riskier without CSP.
- cookies + aliexpress host manifest cookies permission paired with https://*.aliexpress.com/* enables reading AliExpress session cookies.
- operator_cluster siblings=4 store 4 sibling extensions share same dev email fingerprint; +2.5 webstore signal.
- privacy_policy third_party_sharing=true, retention=false api Policy scoped and acknowledges collection, but no retention period and shares with third parties.
- developer_name empty store No 'Offered by' display name; reduces identity accountability.
- js_external_hosts includes retail domains crx External host list includes abercrombie, adidas, academy etc — consistent with multi-retailer cart sharing.
- cve_findings_raw empty crx No CVEs detected in bundled libraries; react 17.0.2 in use.
Permissions Breakdown
- alarms low Scheduling only; minimal risk.
- clipboardWrite medium Can overwrite user clipboard content silently.
- storage low Local extension data storage.
- unlimitedStorage low Allows large local data; minor escalation of storage.
- tabs medium Can read tab URLs and metadata across sessions.
- cookies high Can read/write cookies; scoped to host_permissions but includes AliExpress.
- activeTab low Transient access to current tab on user action.
- scripting medium Can inject scripts into pages matching host_permissions.
- https://share-a-cart.com/* low Dev-controlled domain; expected for sync/share functionality.
- https://crtsh.net/* low Certificate transparency lookup; unusual but low risk.
- https://*.aliexpress.com/* medium Broad access to AliExpress including cart/session cookies.
Pillar Scores
Permissions5.30
Reputation5.50
Network2.00
Webstore5.00
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00
Operator Siblings (4)
Other extensions sharing this developer's compound fingerprint:
Scoring History
| v3.6 | 3.26 | Low | review | 2026-06-16 |
| v3.4-rev | 3.76 | Low | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA
0b45b2bafae1…
Force block
— not fired
Score recovered
no
Elapsed
28.3s