BestBuy Search By Image
nppjmiadmakeigiagilkfffplihgjlec
Risk Score
5.69
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack sends users to saxsos.xyz — clear monetization/tracking intent.
- Privacy policy admits data collection and third-party sharing without scoping to this extension (+10 privacy).
- Free-webmail Gmail dev with no verified publisher; saxsos.xyz domain unknown provenance.
- <all_urls> host permission paired with 9 external JS hosts including social/ad-adjacent endpoints.
- Install count of 5 with HIGH-tier host permission flags tail-attack-surface risk.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() points to saxsos.xyz/p/sorry.html — 3rd-party monetization/tracking domain.
- privacy_policy_generic_with_data_collection_and_sharing api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true — D classification → +10 privacy.
- free_webmail_dev_no_business_site store Developer ecomstal.official uses gmail.com; no verified publisher badge; no recognized org.
- broad_host_permission manifest <all_urls> host permission on a Shopping/image-search tool with 9 external JS hosts.
- small_install_high_perm_anomaly api Only 5 installs but high-tier <all_urls> permission — tail attack surface flagged.
- dom_xss_sink crx result.js: innerHTML written from variable without sanitization; no CSP present — elevated DOM-XSS risk.
- js_external_hosts_diverse crx 9 external hosts: lens.google.com, yandex.com, pinterest.com, t.me, twitter.com, wa.me, facebook.com, saxsos.xyz, chrome.google.com.
- no_csp manifest content_security_policy is null — MV3 strict default applies but DOM sink risk is higher without explicit CSP.
Permissions Breakdown
- contextMenus low Used to add right-click image search menu item; low inherent risk.
- <all_urls> (host_permission) high Grants access to every site the user visits; broad reach with contextMenus for image search.
Pillar Scores
Permissions5.00
Reputation8.00
Network4.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:22
Listing SHA
3bf340dd850a…
Force block
— not fired
Score recovered
no
Elapsed
—