SHEIN Search By Image
mpgaodghdhmeljgogbeagpbhgdbfofgb
Risk Score
4.27
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack sends users to developer-controlled domain saxsos.xyz — classic monetization/tracking abuse.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic policy).
- Free-webmail developer (gmail), no verified publisher, no business identity — minimal accountability.
- <all_urls> host permission with 9 external JS hosts including social networks and saxsos.xyz developer domain.
- Small-install + high-permission anomaly (15 installs, <all_urls>) raises tail-attack-surface concern.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL points to https://www.saxsos.xyz/p/sorry.html — 3rd-party monetization pattern.
- privacy_policy_generic_with_data_collection_and_3p_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- free_webmail_dev_no_business store Developer email ecomstal.official@gmail.com; no verified publisher; developer_domain gmail.com.
- host_permissions_all_urls manifest <all_urls> host permission granted with 9 external JS hosts including saxsos.xyz, social platforms.
- install_perm_anomaly api 15 installs with high-tier permission (<all_urls>); small_install_high_perm=true.
- dom_sink_innerhtml_userctrl crx result.js uses innerHTML with variable input; no CSP present — elevated DOM-XSS risk.
- no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP hardens the innerHTML finding.
- js_external_hosts_breadth crx 9 distinct external hosts contacted including yandex.com, t.me, wa.me, www.saxsos.xyz.
Permissions Breakdown
- contextMenus low Adds right-click menu items; limited impact on its own.
- <all_urls> (host_permission) high Grants access to all websites; combined with content scripts or requests enables broad data access.
Pillar Scores
Permissions5.00
Reputation7.50
Network4.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 16:38
Listing SHA
3ea80f055c8d…
Force block
— not fired
Score recovered
no
Elapsed
—