AiPrice(AliPrice) Search by Image for Amazon
nhfmioilpglanakdpomfobcmbkbjedha
Risk Score
5.03
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies permission paired with broad host access on Amazon/eBay/Walmart enables session token and PII exfiltration.
- Privacy policy fetched but scope_extension=false and data_collection+third_party_sharing=true: policy admits sharing without scoping to this extension.
- Brand impersonation: extension is not a verified Amazon affiliate yet uses 'Amazon' in title and targets all Amazon domains.
- No CSP + innerHTML DOM-XSS sink + new Function() constructor increases XSS attack surface on injected content.
- 12 external JS hosts contacted (aiprice.com, aliprice.com subdomains + github.com) with no CSP limiting exfil destinations.
Evidence
- cookies + broad host permissions on major retail sites manifest cookies perm + host_permissions covering Amazon (16 TLDs), eBay, Walmart, Wish, AliExpress, GA.
- privacy policy admits data collection & 3rd-party sharing without extension scope api privacy_policy_classification: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
- brand impersonation — amazon store brand_mention.is_impersonation=true for 'amazon'; confirmed_owner=false; not verified publisher of Amazon.
- no content_security_policy crx content_security_policy=null on MV3 extension; amplifies DOM-XSS and new Function() risks.
- function_constructor in vendor bundle crx new Function() call in chunk-vendors-6185be05.js; dynamic code execution risk.
- dom_sink_innerhtml_userctrl + no CSP crx innerHTML sink in chunk-vendors-aacc2dbb.js with csp_present=false → elevated DOM-XSS (+2.0 FIX B).
- 12 external JS hosts including github.com crx js_external_hosts has 12 entries across aiprice.com, aliprice.com subdomains and github.com.
- verified publisher + featured by Google store verified_publisher=true, is_featured_by_google=true; applied reputation discounts per rubric.
Permissions Breakdown
- activeTab low Scoped to user-activated tab only; low standalone risk.
- alarms low Schedules background tasks; minimal direct risk.
- contextMenus low Adds right-click menu items; limited capability.
- cookies high Can read/write cookies across declared host origins including Amazon, eBay, Walmart.
- notifications low Can push desktop notifications; moderate nuisance risk only.
- storage low Local extension storage; low risk in isolation.
- *://*.aliexpress.com/* high Broad host access to major e-commerce site; cookies+host = session risk.
- *://*.amazon.com/* (and all regional TLDs) high Cookies paired with host access on Amazon domains enables session/PII exfil.
- *://*.ebay.com/* high Cookies + host access on eBay; same session-theft surface.
- *://*.walmart.com/* medium Content-script host access to Walmart; no stated functional need beyond price.
- *://*.wish.com/* medium Host access to Wish; within stated price-comparison function.
- *://ssl.google-analytics.com/* medium Explicit GA analytics host permission; extension can intercept analytics calls.
Pillar Scores
Permissions5.50
Reputation4.50
Network3.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA
9160c3d320d0…
Force block
— not fired
Score recovered
no
Elapsed
33.8s