Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SHEIN Search By Image

mpgaodghdhmeljgogbeagpbhgdbfofgb
Risk Score
4.27
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Shopping
Installs 15
Rating
Last updated 2026-05-15 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer ecomstal.official@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack sends users to developer-controlled domain saxsos.xyz — classic monetization/tracking abuse.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic policy).
  • Free-webmail developer (gmail), no verified publisher, no business identity — minimal accountability.
  • <all_urls> host permission with 9 external JS hosts including social networks and saxsos.xyz developer domain.
  • Small-install + high-permission anomaly (15 installs, <all_urls>) raises tail-attack-surface concern.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL points to https://www.saxsos.xyz/p/sorry.html — 3rd-party monetization pattern.
  • privacy_policy_generic_with_data_collection_and_3p_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • free_webmail_dev_no_business store Developer email ecomstal.official@gmail.com; no verified publisher; developer_domain gmail.com.
  • host_permissions_all_urls manifest <all_urls> host permission granted with 9 external JS hosts including saxsos.xyz, social platforms.
  • install_perm_anomaly api 15 installs with high-tier permission (<all_urls>); small_install_high_perm=true.
  • dom_sink_innerhtml_userctrl crx result.js uses innerHTML with variable input; no CSP present — elevated DOM-XSS risk.
  • no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP hardens the innerHTML finding.
  • js_external_hosts_breadth crx 9 distinct external hosts contacted including yandex.com, t.me, wa.me, www.saxsos.xyz.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; limited impact on its own.
  • <all_urls> (host_permission) high Grants access to all websites; combined with content scripts or requests enables broad data access.

Pillar Scores

Permissions5.00
Reputation7.50
Network4.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 16:38
Listing SHA 3ea80f055c8d…
Force block — not fired
Score recovered no
Elapsed