Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Share-A-Cart for Instacart

nlhfmidcpehddipkjeegjgdkdafekaem
Risk Score
4.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 384
Rating 5.0
Last updated 2026-04-21 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@share-a-cart.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + https://*/* broad host access: can exfiltrate session cookies from any site visited.
  • 5 innerHTML DOM-XSS sinks across multiple JS files with no CSP; XSS exploitation surface is wide.
  • 4 sibling extensions under same operator fingerprint increases blast radius if one is compromised.
  • Privacy policy admits data collection and third-party sharing but no retention period disclosed.
  • No developer name listed; small install base with high-tier permissions (install_perm_anomaly).

Evidence

  • broad_host_permissions_with_cookies manifest cookies + https://*/* + http://*/* grants read/write access to cookies on all sites.
  • dom_xss_sinks_no_csp crx 5 files with innerHTML assignments from variables; csp_present=false amplifies risk per FIX B.
  • operator_cluster_siblings store 4 sibling extensions share same dev email and CSP host fingerprint.
  • privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • no_developer_name store developer_name field is empty; reputation starts elevated at 5.0.
  • small_install_high_perm_anomaly api 384 installs with HIGH-tier permissions (cookies, scripting, broad host).
  • react_17_no_cve crx React 17.0.2 bundled; no CVEs found in cve_findings_raw. CVE pillar = 0.
  • is_featured_by_google store Extension carries Google Featured badge; partial reputation credit applied.

Permissions Breakdown

  • alarms low Scheduling only; minimal risk.
  • clipboardWrite medium Can write to clipboard; share-cart function plausible but unverified.
  • storage low Local data persistence; standard.
  • unlimitedStorage low Allows large local storage; low direct harm.
  • tabs medium Can query tab URLs and metadata across sessions.
  • cookies high Can read/write cookies; paired with broad host access, high risk.
  • activeTab low Scoped to user-activated tab only.
  • scripting high Programmatic script injection into pages; broad host permissions amplify.
  • https://*/* high Broad host access across all HTTPS sites.
  • http://*/* high Broad host access across all HTTP sites.

Pillar Scores

Permissions6.00
Reputation5.50
Network2.50
Webstore5.00
Maintenance0.00
Privacy2.00
Code Quality5.00
CVE Exposure0.00

Operator Siblings (4)

Other extensions sharing this developer's compound fingerprint:

Scoring History

v3.6 4.08 Medium review 2026-06-16
v3.4-rev 4.68 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA bdd380c17dbe…
Force block — not fired
Score recovered no
Elapsed 28.2s