Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Walmart Search By Image

mcaihdkeijgfhnlfcdehniplmaapadgb
Risk Score
4.27
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Shopping
Installs 20
Rating
Last updated 2026-05-15 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer ecomstal.official@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack to saxsos.xyz — telemetry/tracking on removal, classic monetization-shell signal.
  • Privacy policy admits data collection and third-party sharing without scoping to this extension (+10 privacy).
  • Free-webmail Gmail developer with no verified business identity; saxsos.xyz is unvalidated throwaway domain.
  • Broad <all_urls> host permission on a 20-install Shopping extension is disproportionate tail-attack surface.
  • DOM-XSS sink (innerHTML) without CSP — exploitable if search results contain attacker-controlled content.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL targets https://www.saxsos.xyz/p/sorry.html — 3rd-party tracking on removal.
  • privacy_policy_generic_with_sharing store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • free_webmail_dev store Developer email ecomstal.official@gmail.com; no verified business; developer domain gmail.com.
  • install_perm_anomaly api 20 installs + <all_urls> host permission flagged as small_install_high_perm=true.
  • js_external_hosts crx 9 external hosts including saxsos.xyz, yandex.com, t.me, wa.me — broad social/search reach.
  • dom_sink_innerhtml_no_csp crx innerHTML user-controlled sink in result.js; csp_present=false amplifies DOM-XSS risk.
  • host_permission_all_urls manifest <all_urls> host permission declared; MV3 extension with no CSP and 9 external JS hosts.
  • install_url_hijack crx onInstalled opens welcome.html — internal but combined with uninstall hijack signals monetization pattern.

Permissions Breakdown

  • contextMenus low Used to add right-click image search menu item; low standalone risk.
  • <all_urls> (host_permission) high Grants access to all URLs; combined with contextMenus enables broad data reach.

Pillar Scores

Permissions5.00
Reputation8.00
Network4.50
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 15:20
Listing SHA d391d0f4f7d0…
Force block — not fired
Score recovered no
Elapsed