Amazon Product Scraper | 10X
mnacfoefejolpobogooghoclppjcgfcm
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension — scores maximum privacy risk.
- Gmail developer email with no verified publisher; brand_mention flags Amazon impersonation.
- Content scripts injected across 20+ Amazon regional domains; scraped data sent to unknown ecomstal.com crawler endpoints.
- No CSP (csp_present=false, MV3) combined with innerHTML DOM-XSS sink in main.js.
- Hosts span 3 countries (CN, IE, US) including China-geolocated infrastructure for a scraper tool.
Evidence
- privacy_policy_admits_3p_sharing_not_scoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5-D applies: +10.0 privacy.
- brand_impersonation_amazon store brand_mention.is_impersonation=true, confirmed_owner=false, developer_domain=gmail.com.
- third_party_crawler_hosts manifest Host perms include searchcrwler-a/b.ecomstal.com — unknown crawler infra receiving Amazon scraped data.
- free_webmail_dev_no_verified_publisher store Developer email 10xprofitio@gmail.com; verified_publisher=false; is_featured_by_google=false.
- dom_xss_sink_no_csp crx innerHTML user-controlled sink in main.js with csp_present=false raises XSS risk.
- geo_diversity_cn_ie_us crx JS external hosts span 3 countries including CN; not VPN/translation category.
- operator_cluster_dev_email_siblings api dev_email dimension sibling_count=2 indicates same gmail account owns other extensions.
- tos_violation_amazon_scraper store Extension explicitly scrapes Amazon product data to CSV — violates Amazon ToS (v3.1 rule 7).
Permissions Breakdown
- activeTab low Grants access only to currently active tab on user action; limited scope.
- storage low Local data persistence; low standalone risk.
- scripting medium Allows programmatic script injection into pages; elevated with host permissions.
- *://*.amazon.com/* (and 20+ amazon domains) high Broad host access across all Amazon regional domains enables scraping/reading all page content.
- https://searchcrwler-a.ecomstal.com/* + https://searchcrwler-b.ecomstal.com/* high Unknown third-party crawler service; data may be exfiltrated there.
- https://app.10xprofit.io/* medium Developer backend; scraped data likely sent here.
- http://localhost:3000/* low Localhost access — likely dev artifact; low external risk.
Pillar Scores
Permissions4.50
Reputation7.50
Network4.50
Webstore5.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:21
Listing SHA
309c0e4fae48…
Force block
— not fired
Score recovered
no
Elapsed
—