Recipe Reader & Grocery Finder | Ceres Cart
nckacfgoolkhaedphbknecabckccgffe
Risk Score
3.73
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's own account policy — not scoped to this extension; data collection admitted with no extension-specific disclosure.
- Content scripts injected on ALL http/https origins despite Shopping-tool claim; broad DOM access on every site visited.
- Dynamic <script> creation and new Function() constructor present in bundle — no CSP to constrain dynamic code execution.
- No developer name listed despite verified-publisher status; identity accountability gap.
- External JS hosts include react.dev and www.i18next.com — third-party origin contact without CSP guard.
Evidence
- broad_content_scripts manifest content_scripts_matches includes http://*/* and https://*/* — full-web DOM injection beyond stated grocery/recipe scope.
- privacy_policy_generic store Privacy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — v3.5-D applies → +10.
- dynamic_script_and_function_constructor crx script_src_dynamic + function_constructor in SettingsScreen.js and CountrySelector.js; no CSP to restrict execution.
- no_csp manifest content_security_policy is null; MV3 default CSP applies but dynamic script creation still flagged.
- verified_publisher_featured store Extension is verified and featured by Google; discounts applied but capped at floor 2.0 for reputation.
- external_js_hosts crx 6 external hosts: cerescart.com, nominatim.openstreetmap.org, react.dev, www.amazon.com, www.i18next.com, www.kroger.com.
- no_developer_name store developer_name is empty string despite verified publisher badge — accountability gap.
- no_bad_hosts_no_monetization api threat_intel shows no bad_host_hits, monetization_hits, or affiliate_hits; domain resolves and is not throwaway.
Permissions Breakdown
- storage low Local data persistence; low abuse potential alone.
- tabs medium Can read tab URLs/titles across all open tabs.
- content_scripts: http://*/* + https://*/* high Broad content-script injection on all HTTP/HTTPS sites — full page DOM access everywhere.
Pillar Scores
Permissions4.50
Reputation2.00
Network2.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-07-08 14:01
Listing SHA
85bc5428b53e…
Force block
— not fired
Score recovered
no
Elapsed
—