Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shopify Theme File Search by EZFY

mhchmhfecfdpaifljcfebnlaiaphfkmb
Risk Score
2.95
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 20,000
Rating 3.5
Last updated 2026-05-16 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer diego.boarutto.fortes@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • script_src_dynamic in popup+background bundles: dynamic script injection surface even under strict CSP.
  • function_constructor (new Function) in popup+background: code execution primitive, potential CSP bypass.
  • innerHTML sinks in 4 files including contentScript injected on Shopify admin: DOM-XSS risk against Shopify store data.
  • Developer uses personal Gmail; brand_mention confirms Shopify impersonation flag with no verified-publisher status.
  • Privacy policy admits data collection and third-party sharing but no retention period disclosed.

Evidence

  • script_src_dynamic crx Dynamic <script> element creation found in popup.bundle.js and background.bundle.js — webpack lazy-loading pattern but still a code-injection surface.
  • function_constructor crx new Function() used in popup.bundle.js and background.bundle.js; enables dynamic code execution at runtime.
  • dom_sink_innerhtml_userctrl crx innerHTML sinks in 4 bundles including contentScript running on https://*.myshopify.com/admin/* — XSS risk on merchant admin.
  • brand_impersonation store brand_mention.is_impersonation=true for 'shopify'; developer is not confirmed owner; uses gmail.com address.
  • free_webmail_developer store Developer email is diego.boarutto.fortes@gmail.com; no verified publisher badge; reputation floor triggered at 7.5.
  • privacy_policy_third_party_sharing api Privacy policy fetched, scoped to extension, but third_party_sharing=true and retention=false — not fully adequate.
  • content_scripts_shopify_admin manifest Content scripts injected on https://*.myshopify.com/admin/* and https://admin.shopify.com/store/* — high-value merchant data scope.
  • cve_findings crx No CVEs detected in bundled JS libraries; cve_findings_raw is empty.

Permissions Breakdown

  • storage low Standard local data persistence; low risk.
  • activeTab low Access only to the active tab on user gesture; scoped and transient.
  • windows medium Can read/manipulate browser windows; moderate capability.
  • tabs medium Can read tab URLs and metadata across tabs.
  • identity low OAuth token access; no broad scopes declared.

Pillar Scores

Permissions2.30
Reputation7.50
Network0.00
Webstore3.50
Maintenance0.00
Privacy2.00
Code Quality7.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA 9103690c1093…
Force block — not fired
Score recovered no
Elapsed 30.2s