Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AiPrice(AliPrice) Search by Image for Amazon

nhfmioilpglanakdpomfobcmbkbjedha
Risk Score
5.03
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 10,000
Rating 5.0
Last updated 2026-05-27 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer hui.song@aiprice.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies permission paired with broad host access on Amazon/eBay/Walmart enables session token and PII exfiltration.
  • Privacy policy fetched but scope_extension=false and data_collection+third_party_sharing=true: policy admits sharing without scoping to this extension.
  • Brand impersonation: extension is not a verified Amazon affiliate yet uses 'Amazon' in title and targets all Amazon domains.
  • No CSP + innerHTML DOM-XSS sink + new Function() constructor increases XSS attack surface on injected content.
  • 12 external JS hosts contacted (aiprice.com, aliprice.com subdomains + github.com) with no CSP limiting exfil destinations.

Evidence

  • cookies + broad host permissions on major retail sites manifest cookies perm + host_permissions covering Amazon (16 TLDs), eBay, Walmart, Wish, AliExpress, GA.
  • privacy policy admits data collection & 3rd-party sharing without extension scope api privacy_policy_classification: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
  • brand impersonation — amazon store brand_mention.is_impersonation=true for 'amazon'; confirmed_owner=false; not verified publisher of Amazon.
  • no content_security_policy crx content_security_policy=null on MV3 extension; amplifies DOM-XSS and new Function() risks.
  • function_constructor in vendor bundle crx new Function() call in chunk-vendors-6185be05.js; dynamic code execution risk.
  • dom_sink_innerhtml_userctrl + no CSP crx innerHTML sink in chunk-vendors-aacc2dbb.js with csp_present=false → elevated DOM-XSS (+2.0 FIX B).
  • 12 external JS hosts including github.com crx js_external_hosts has 12 entries across aiprice.com, aliprice.com subdomains and github.com.
  • verified publisher + featured by Google store verified_publisher=true, is_featured_by_google=true; applied reputation discounts per rubric.

Permissions Breakdown

  • activeTab low Scoped to user-activated tab only; low standalone risk.
  • alarms low Schedules background tasks; minimal direct risk.
  • contextMenus low Adds right-click menu items; limited capability.
  • cookies high Can read/write cookies across declared host origins including Amazon, eBay, Walmart.
  • notifications low Can push desktop notifications; moderate nuisance risk only.
  • storage low Local extension storage; low risk in isolation.
  • *://*.aliexpress.com/* high Broad host access to major e-commerce site; cookies+host = session risk.
  • *://*.amazon.com/* (and all regional TLDs) high Cookies paired with host access on Amazon domains enables session/PII exfil.
  • *://*.ebay.com/* high Cookies + host access on eBay; same session-theft surface.
  • *://*.walmart.com/* medium Content-script host access to Walmart; no stated functional need beyond price.
  • *://*.wish.com/* medium Host access to Wish; within stated price-comparison function.
  • *://ssl.google-analytics.com/* medium Explicit GA analytics host permission; extension can intercept analytics calls.

Pillar Scores

Permissions5.50
Reputation4.50
Network3.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA 9160c3d320d0…
Force block — not fired
Score recovered no
Elapsed 33.8s