Shopify Theme Detector
npjkomjipdbengebpldgodddlinfjhhm
Risk Score
6.11
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Brand impersonation: extension mentions 'Shopify' but developer is unaffiliated (scanwp.net), no verified publisher badge.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- Three medium-severity CVEs in bundled jquery@1.11.3 (XSS); library far behind fixed versions.
- Content scripts run on <all_urls> with 26 months without update — stale, high-reach attack surface.
- No developer name listed; low rating (3.4) increases credibility concern.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'shopify'; confirmed_owner=false; developer is scanwp.net.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- cve_jquery_medium crx 3 medium CVEs in jquery@1.11.3 (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed_in up to 3.5.0.
- content_scripts_all_urls manifest content_scripts_matches=["<all_urls>"] — extension runs on every visited page.
- stale_extension store Last updated April 2024; months_since_update=26, triggering +8.5 maintenance score.
- no_developer_name store developer_name is empty string; only info@scanwp.net available.
- script_src_dynamic crx jquery.min.js creates dynamic <script> elements — scores +3.0 code quality.
- triple_stale_fingerprint store >24mo + CVEs present + MV3 (MV2 rule N/A) — v2 calibration +2.0 webstore applied for stale+CVE combo.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.11.3 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.11.3 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.11.3 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- scripting medium Can inject scripts into pages; paired with <all_urls> content_scripts raises reach.
- tabs medium Can read tab URLs and metadata across all tabs.
- content_scripts:<all_urls> high Scripts execute on every site the user visits, broad data access surface.
Pillar Scores
Permissions4.50
Reputation7.00
Network0.00
Webstore5.50
Maintenance8.50
Privacy10.00
Code Quality3.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA
ac69b7c9c212…
Force block
— not fired
Score recovered
no
Elapsed
27.3s