Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AliExpress Quick Currency & Price Converter

mcaglpclodnaiimhicpjemhcinjfnjce
Risk Score
4.86
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 5
Rating
Last updated 2026-05-12 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer ecomstal.official@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack to saxsos.xyz — classic monetization/tracking shell pattern.
  • Privacy policy admits data collection and third-party sharing without scoping to this extension (D rule: +10.0 privacy).
  • Free-webmail developer (gmail) with no verified business domain; saxsos.xyz used as primary backend.
  • JS external host saxsos.xyz contacts extension backend; policy on same domain is unscoped.
  • Install URL hijack to welcome.html with external host suggests onboarding funnel to saxsos.xyz.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL -> https://www.saxsos.xyz/p/sorry.html (3rd-party domain).
  • install_url_hijack crx onInstalled opens welcome.html; js_external_hosts includes www.saxsos.xyz.
  • privacy_policy_unscoped_with_sharing store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — D rule triggers +10.0.
  • free_webmail_developer store Developer email ecomstal.official@gmail.com; no verified business domain; reputation floor 7.5.
  • js_external_host crx Extension loads/contacts www.saxsos.xyz — same domain as privacy policy and uninstall URL.
  • no_csp crx content_security_policy is null / csp_present=false; MV3 mitigates but no explicit CSP declared.
  • very_low_install_count store Only 5 installs; new/unproven extension with no ratings.
  • host_geo_diversity api JS hosts span RU, SG, US (3 countries); below +1.5 threshold of 4.

Permissions Breakdown

  • storage low Stores user preferences locally; low standalone risk.
  • *://*.aliexpress.com/* medium Scoped host access to AliExpress; content scripts can read/modify page content.
  • *://*.aliexpress.ru/* medium Same risk surface as aliexpress.com host permission.
  • *://*.aliexpress.us/* medium Same risk surface as aliexpress.com host permission.
  • *://*.aliexpress.bn/* medium Additional AliExpress TLD host permission.
  • *://*.aliexpress.is/* medium Additional AliExpress TLD host permission.
  • *://*.aliexpress.pk/* medium Additional AliExpress TLD host permission.

Pillar Scores

Permissions2.00
Reputation7.50
Network2.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 15:20
Listing SHA c00f165ff3d8…
Force block — not fired
Score recovered no
Elapsed