Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

EverBee - Find Best Selling Products on Etsy

oeicpkgdngoghobnbjngekclpcmpgpij
Risk Score
4.46
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 200,000
Rating 4.7
Last updated 2026-08-25 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer cody@everbee.io
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own account policy — not scoped to this extension; data collection and third-party sharing admitted with no extension context.
  • <all_urls> host permission + scripting enable full page read/write on every site, far beyond stated Etsy focus.
  • Content scripts injected on ChatGPT, Claude, Gemini — AI chat content exposure is a significant overstep for an Etsy product tool.
  • install_url_hijack and uninstall_url_hijack flags set; targets not captured but pattern warrants review.
  • React 16.13.1 bundled — below the high-CVE threshold (16.4) referenced in rubric; no CVEs detected today but outdated.

Evidence

  • host_permissions=<all_urls> + scripting manifest Full cross-site script injection capability declared despite narrow Etsy use-case.
  • content_scripts on AI chat platforms manifest Scripts injected into chatgpt.com, claude.ai, gemini.google.com — out-of-scope for Etsy product research.
  • privacy_policy_url is Google account policy store URL https://myaccount.google.com/privacypolicy is Google's own policy; scope_extension=false, third_party_sharing=true.
  • install_url_hijack=true / uninstall_url_hijack=true crx Extension sets install/uninstall URLs; targets null in scan but pattern flagged by detector.
  • js_external_hosts includes AI platform domains crx chatgpt.com, claude.ai, gemini.google.com, generativelanguage.googleapis.com in JS host list.
  • react@16.13.1 bundled crx React below 16.4 trigger threshold; no CVEs found in cve_findings_raw but version is stale.
  • is_featured_by_google=true store Featured badge applies reputation discount but does not override privacy or scope concerns.
  • operator_cluster sibling_count=0, no bad_host_hits, no monetization_hits api No cluster or threat-intel signals; clean on those dimensions.

Permissions Breakdown

  • storage low Stores local state; low standalone risk.
  • tabs medium Can read tab URLs and titles across sessions.
  • activeTab medium Script injection on user-active tab; scoped but broad in practice.
  • clipboardWrite medium Can write to clipboard silently; potential data-injection vector.
  • downloads medium Can trigger file downloads without explicit user file-picker.
  • scripting high Programmatic script injection into pages; high capability when paired with <all_urls>.
  • <all_urls> (host_permission) high Grants content script and scripting API access to every site visited.

Pillar Scores

Permissions5.50
Reputation4.00
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedn648b98fbdp727562726963xsx 4.34 Medium review 2026-09-07
sssiedn0d33bf5ddp727562726963xsx 4.01 Medium review 2026-08-26
<fsssiedx{$"sssiedx 4.77 Medium review 2026-08-20
<fsssiedxh"sssiedx 4.28 Medium review 2026-08-20
<fsssiedxh$"sssiedx 4.30 Medium review 2026-08-20
xx pfsssiedxm<sssiedx 4.24 Medium review 2026-08-20
%22fsssiedxmfdsaxax><!--></ScRiPt>asddsssiedx 4.56 Medium review 2026-08-20
%27fsssiedxm"sssiedx 4.47 Medium review 2026-08-20
&#x27;fsssiedxm'sssiedx 4.28 Medium review 2026-08-20
4.52 Medium review 2026-08-20
fsssiedxm$"sssiedx 4.31 Medium review 2026-08-20
<fsssiedxi"sssiedx 4.04 Medium review 2026-07-28
<fsssiedxi$"sssiedx 2.95 Low review 2026-07-28
fsssiedx<sssiedx 4.01 Medium review 2026-07-28
fsssiedxa"sssiedx 4.12 Medium review 2026-07-28
fsssiedxa$'sssiedx 4.05 Medium review 2026-07-28
fsssiedxa$"sssiedx 4.18 Medium review 2026-07-28
sssieddrubricxsx 4.35 Medium review 2026-07-28
v3.6 4.46 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA 907472dfc094…
Force block — not fired
Score recovered no
Elapsed 24.6s