Export My NFT Listings
lpmogjockhdkcepliphdfbhpcdacbhki
Risk Score
6.07
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Abandoned: last updated Dec 2021 (54 months ago), unpatched against any future platform changes or security issues.
- Privacy policy points to generic Google policy (scope_extension=false, admits data collection and 3rd-party sharing) — effectively no extension-scoped policy.
- webRequest permission can observe all network traffic on NFT marketplace hosts, including wallet and authentication data.
- Developer domain itjesse.com does not resolve — no accountability or support channel.
- function_constructor pattern in 4 bundled JS files without CSP; no content_security_policy declared.
Evidence
- abandoned_extension store Last updated December 2021; 54 months since update — no maintenance for 4.5 years.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_domain_dead api itjesse.com does not resolve per threat_intel; no reachable developer contact or policy page.
- no_csp manifest content_security_policy is null (MV3); no additional script-src hardening declared.
- function_constructor crx new Function() found in popup.js, nftrade.js, scv.js, opensea.js — dynamic code construction pattern.
- webRequest_high_perm manifest webRequest declared with access to NFT marketplace hosts including wallet-bearing OpenSea sessions.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; low-install extension with high-tier permissions.
- featured_by_google store is_featured_by_google=true; partial trust signal but does not offset abandonment or privacy gaps.
Permissions Breakdown
- clipboardWrite medium Can write to clipboard; used for CSV export but permits silent data injection.
- tabs medium Access to tab URLs and navigation; medium risk in combination with scripting.
- webRequest high Can observe all network requests to permitted hosts; allows traffic interception.
- background low Keeps service worker alive; low risk alone.
- storage low Local extension storage; standard, low risk.
- scripting medium Can inject scripts into permitted host origins; medium risk scoped to declared hosts.
- host:https://nftrade.com/ medium Scoped to NFT marketplace; consistent with stated function.
- host:https://api.nftrade.com/ medium Scoped to NFTrade API; consistent with stated function.
- host:https://scv.finance/ medium Scoped to SCV Finance NFT portfolio; consistent with stated function.
- host:https://opensea.io/ medium Scoped to OpenSea; consistent with stated function.
- host:https://api.opensea.io/ medium Scoped to OpenSea API; consistent with stated function.
Pillar Scores
Permissions4.50
Reputation5.50
Network3.50
Webstore3.00
Maintenance10.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA
140c230f8611…
Force block
— not fired
Score recovered
no
Elapsed
27.8s