Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

BestBuy Search By Image

nppjmiadmakeigiagilkfffplihgjlec
Risk Score
5.69
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Shopping
Installs 5
Rating
Last updated 2026-05-20 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer ecomstal.official@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack sends users to saxsos.xyz — clear monetization/tracking intent.
  • Privacy policy admits data collection and third-party sharing without scoping to this extension (+10 privacy).
  • Free-webmail Gmail dev with no verified publisher; saxsos.xyz domain unknown provenance.
  • <all_urls> host permission paired with 9 external JS hosts including social/ad-adjacent endpoints.
  • Install count of 5 with HIGH-tier host permission flags tail-attack-surface risk.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() points to saxsos.xyz/p/sorry.html — 3rd-party monetization/tracking domain.
  • privacy_policy_generic_with_data_collection_and_sharing api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true — D classification → +10 privacy.
  • free_webmail_dev_no_business_site store Developer ecomstal.official uses gmail.com; no verified publisher badge; no recognized org.
  • broad_host_permission manifest <all_urls> host permission on a Shopping/image-search tool with 9 external JS hosts.
  • small_install_high_perm_anomaly api Only 5 installs but high-tier <all_urls> permission — tail attack surface flagged.
  • dom_xss_sink crx result.js: innerHTML written from variable without sanitization; no CSP present — elevated DOM-XSS risk.
  • js_external_hosts_diverse crx 9 external hosts: lens.google.com, yandex.com, pinterest.com, t.me, twitter.com, wa.me, facebook.com, saxsos.xyz, chrome.google.com.
  • no_csp manifest content_security_policy is null — MV3 strict default applies but DOM sink risk is higher without explicit CSP.

Permissions Breakdown

  • contextMenus low Used to add right-click image search menu item; low inherent risk.
  • <all_urls> (host_permission) high Grants access to every site the user visits; broad reach with contextMenus for image search.

Pillar Scores

Permissions5.00
Reputation8.00
Network4.00
Webstore8.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:22
Listing SHA 3bf340dd850a…
Force block — not fired
Score recovered no
Elapsed