Share-A-Cart for Instacart
nlhfmidcpehddipkjeegjgdkdafekaem
Risk Score
4.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies + https://*/* broad host access: can exfiltrate session cookies from any site visited.
- 5 innerHTML DOM-XSS sinks across multiple JS files with no CSP; XSS exploitation surface is wide.
- 4 sibling extensions under same operator fingerprint increases blast radius if one is compromised.
- Privacy policy admits data collection and third-party sharing but no retention period disclosed.
- No developer name listed; small install base with high-tier permissions (install_perm_anomaly).
Evidence
- broad_host_permissions_with_cookies manifest cookies + https://*/* + http://*/* grants read/write access to cookies on all sites.
- dom_xss_sinks_no_csp crx 5 files with innerHTML assignments from variables; csp_present=false amplifies risk per FIX B.
- operator_cluster_siblings store 4 sibling extensions share same dev email and CSP host fingerprint.
- privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- no_developer_name store developer_name field is empty; reputation starts elevated at 5.0.
- small_install_high_perm_anomaly api 384 installs with HIGH-tier permissions (cookies, scripting, broad host).
- react_17_no_cve crx React 17.0.2 bundled; no CVEs found in cve_findings_raw. CVE pillar = 0.
- is_featured_by_google store Extension carries Google Featured badge; partial reputation credit applied.
Permissions Breakdown
- alarms low Scheduling only; minimal risk.
- clipboardWrite medium Can write to clipboard; share-cart function plausible but unverified.
- storage low Local data persistence; standard.
- unlimitedStorage low Allows large local storage; low direct harm.
- tabs medium Can query tab URLs and metadata across sessions.
- cookies high Can read/write cookies; paired with broad host access, high risk.
- activeTab low Scoped to user-activated tab only.
- scripting high Programmatic script injection into pages; broad host permissions amplify.
- https://*/* high Broad host access across all HTTPS sites.
- http://*/* high Broad host access across all HTTP sites.
Pillar Scores
Permissions6.00
Reputation5.50
Network2.50
Webstore5.00
Maintenance0.00
Privacy2.00
Code Quality5.00
CVE Exposure0.00
Operator Siblings (4)
Other extensions sharing this developer's compound fingerprint:
Scoring History
| v3.6 | 4.08 | Medium | review | 2026-06-16 |
| v3.4-rev | 4.68 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA
bdd380c17dbe…
Force block
— not fired
Score recovered
no
Elapsed
28.2s