Shopify Theme File Search by EZFY
mhchmhfecfdpaifljcfebnlaiaphfkmb
Risk Score
2.95
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- script_src_dynamic in popup+background bundles: dynamic script injection surface even under strict CSP.
- function_constructor (new Function) in popup+background: code execution primitive, potential CSP bypass.
- innerHTML sinks in 4 files including contentScript injected on Shopify admin: DOM-XSS risk against Shopify store data.
- Developer uses personal Gmail; brand_mention confirms Shopify impersonation flag with no verified-publisher status.
- Privacy policy admits data collection and third-party sharing but no retention period disclosed.
Evidence
- script_src_dynamic crx Dynamic <script> element creation found in popup.bundle.js and background.bundle.js — webpack lazy-loading pattern but still a code-injection surface.
- function_constructor crx new Function() used in popup.bundle.js and background.bundle.js; enables dynamic code execution at runtime.
- dom_sink_innerhtml_userctrl crx innerHTML sinks in 4 bundles including contentScript running on https://*.myshopify.com/admin/* — XSS risk on merchant admin.
- brand_impersonation store brand_mention.is_impersonation=true for 'shopify'; developer is not confirmed owner; uses gmail.com address.
- free_webmail_developer store Developer email is diego.boarutto.fortes@gmail.com; no verified publisher badge; reputation floor triggered at 7.5.
- privacy_policy_third_party_sharing api Privacy policy fetched, scoped to extension, but third_party_sharing=true and retention=false — not fully adequate.
- content_scripts_shopify_admin manifest Content scripts injected on https://*.myshopify.com/admin/* and https://admin.shopify.com/store/* — high-value merchant data scope.
- cve_findings crx No CVEs detected in bundled JS libraries; cve_findings_raw is empty.
Permissions Breakdown
- storage low Standard local data persistence; low risk.
- activeTab low Access only to the active tab on user gesture; scoped and transient.
- windows medium Can read/manipulate browser windows; moderate capability.
- tabs medium Can read tab URLs and metadata across tabs.
- identity low OAuth token access; no broad scopes declared.
Pillar Scores
Permissions2.30
Reputation7.50
Network0.00
Webstore3.50
Maintenance0.00
Privacy2.00
Code Quality7.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA
9103690c1093…
Force block
— not fired
Score recovered
no
Elapsed
30.2s