Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Amazon Order History Reporter

mgkilgclilajckgnedgjgnfdokkgnibi
Risk Score
3.59
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Shopping
Installs 60,000
Rating 4.3
Last updated 2026-04-13 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer azadextension@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses 'Amazon' in name; developer is not Amazon (gmail dev, unverified).
  • cookies permission scoped to all Amazon storefronts — could read Amazon session cookies.
  • Free-webmail developer (gmail) with no verified business identity for an Amazon-branded extension.
  • Privacy policy fetched but no data retention disclosed and third-party sharing status silent.
  • extensionpay.com in CSP connect-src — monetization backend outside Amazon; not flagged but warrants review.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['amazon']; developer_domain=gmail.com, confirmed_owner=false.
  • free_webmail_developer manifest developer_email=azadextension@gmail.com; no verified business domain; falls under free-webmail+brand-impersonation pattern.
  • cookies_permission_with_amazon_hosts manifest cookies + content_scripts on 16 amazon.* domains; can access Amazon session cookies per MV3 host scope.
  • privacy_policy_gaps api scope_extension=true, data_collection=false, retention=false, third_party_silence=true; incomplete disclosure.
  • extensionpay_connect crx CSP connect-src includes extensionpay.com; payment SaaS outside Amazon ecosystem.
  • no_bad_hosts_no_cves crx cve_findings_raw=[], bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — clean threat-intel scan.
  • clean_code_scan crx code_findings_raw=[]; obfuscation_score=0.0; 3 JS files scanned; no eval, exfil, or redirect signals.
  • recently_updated store months_since_update=2; maintenance risk=0.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; minimal risk.
  • cookies high Can read/write cookies; scoped to amazon.* and azad-extension.co.uk host permissions.
  • storage low Local extension storage; low standalone risk.
  • host: amazon.* medium Content scripts on all Amazon storefronts; matches stated function but grants broad page access.
  • host: azad-extension.co.uk medium Dev-controlled domain for payment/licensing; acceptable but not Amazon-owned.

Pillar Scores

Permissions4.00
Reputation7.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA f723423d7e80…
Force block — not fired
Score recovered no
Elapsed 21.4s