Walmart Search By Image
mcaihdkeijgfhnlfcdehniplmaapadgb
Risk Score
4.27
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack to saxsos.xyz — telemetry/tracking on removal, classic monetization-shell signal.
- Privacy policy admits data collection and third-party sharing without scoping to this extension (+10 privacy).
- Free-webmail Gmail developer with no verified business identity; saxsos.xyz is unvalidated throwaway domain.
- Broad <all_urls> host permission on a 20-install Shopping extension is disproportionate tail-attack surface.
- DOM-XSS sink (innerHTML) without CSP — exploitable if search results contain attacker-controlled content.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL targets https://www.saxsos.xyz/p/sorry.html — 3rd-party tracking on removal.
- privacy_policy_generic_with_sharing store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- free_webmail_dev store Developer email ecomstal.official@gmail.com; no verified business; developer domain gmail.com.
- install_perm_anomaly api 20 installs + <all_urls> host permission flagged as small_install_high_perm=true.
- js_external_hosts crx 9 external hosts including saxsos.xyz, yandex.com, t.me, wa.me — broad social/search reach.
- dom_sink_innerhtml_no_csp crx innerHTML user-controlled sink in result.js; csp_present=false amplifies DOM-XSS risk.
- host_permission_all_urls manifest <all_urls> host permission declared; MV3 extension with no CSP and 9 external JS hosts.
- install_url_hijack crx onInstalled opens welcome.html — internal but combined with uninstall hijack signals monetization pattern.
Permissions Breakdown
- contextMenus low Used to add right-click image search menu item; low standalone risk.
- <all_urls> (host_permission) high Grants access to all URLs; combined with contextMenus enables broad data reach.
Pillar Scores
Permissions5.00
Reputation8.00
Network4.50
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 15:20
Listing SHA
d391d0f4f7d0…
Force block
— not fired
Score recovered
no
Elapsed
—