Amazon BSR Fast-View
nhilffccdbcjcnoopblecppbhalagpaf
Risk Score
4.03
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — triggers maximum privacy score (10.0).
- Brand impersonation flag: developer domain is gmail.com, not amazon.com; confirmed_owner == false.
- Free-webmail developer email (gmail) with no verified business identity raises accountability risk.
- install_url_hijack opens a third-party welcome page on install — minor but indicative of monetization intent.
- Geo-diversity: JS hosts span 4 countries (CN, FR, IE, US) which is elevated for a simple BSR display tool.
Evidence
- privacy_policy_generic api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → triggers D-clause (+10.0 privacy).
- brand_impersonation store brand_mention.is_impersonation=true; developer domain is gmail.com, not amazon; confirmed_owner=false.
- free_webmail_dev store Developer email 10xprofitio@gmail.com; no verified business website; raises reputation pillar.
- install_url_hijack manifest install_url_hijack=true; onInstalled opens pages/welcome.html — monetization/tracking intent indicator.
- geo_diversity crx JS hosts span 4 countries (CN, FR, IE, US); +1.5 network for category not in VPN/Translation/etc.
- host_permissions_scope manifest 21 Amazon regional TLD host_permissions; content_scripts match Amazon only — consistent with stated BSR function.
- no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty — no code-level signals detected.
- maintenance_ok store 5 months since update — within 3-6 month bracket (+1.5 maintenance).
Permissions Breakdown
- storage low Persists local settings/data; no exfil risk on its own.
- *://*.amazon.com/* (and 20 regional amazon domains) medium Content-script access to all Amazon storefronts; narrow to stated function but broad across 21 TLDs.
Pillar Scores
Permissions1.30
Reputation6.50
Network1.50
Webstore4.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 16:41
Listing SHA
e27d100fd15e…
Force block
— not fired
Score recovered
no
Elapsed
—