EverBee - Find Best Selling Products on Etsy
oeicpkgdngoghobnbjngekclpcmpgpij
Risk Score
4.46
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own account policy — not scoped to this extension; data collection and third-party sharing admitted with no extension context.
- <all_urls> host permission + scripting enable full page read/write on every site, far beyond stated Etsy focus.
- Content scripts injected on ChatGPT, Claude, Gemini — AI chat content exposure is a significant overstep for an Etsy product tool.
- install_url_hijack and uninstall_url_hijack flags set; targets not captured but pattern warrants review.
- React 16.13.1 bundled — below the high-CVE threshold (16.4) referenced in rubric; no CVEs detected today but outdated.
Evidence
- host_permissions=<all_urls> + scripting manifest Full cross-site script injection capability declared despite narrow Etsy use-case.
- content_scripts on AI chat platforms manifest Scripts injected into chatgpt.com, claude.ai, gemini.google.com — out-of-scope for Etsy product research.
- privacy_policy_url is Google account policy store URL https://myaccount.google.com/privacypolicy is Google's own policy; scope_extension=false, third_party_sharing=true.
- install_url_hijack=true / uninstall_url_hijack=true crx Extension sets install/uninstall URLs; targets null in scan but pattern flagged by detector.
- js_external_hosts includes AI platform domains crx chatgpt.com, claude.ai, gemini.google.com, generativelanguage.googleapis.com in JS host list.
- react@16.13.1 bundled crx React below 16.4 trigger threshold; no CVEs found in cve_findings_raw but version is stale.
- is_featured_by_google=true store Featured badge applies reputation discount but does not override privacy or scope concerns.
- operator_cluster sibling_count=0, no bad_host_hits, no monetization_hits api No cluster or threat-intel signals; clean on those dimensions.
Permissions Breakdown
- storage low Stores local state; low standalone risk.
- tabs medium Can read tab URLs and titles across sessions.
- activeTab medium Script injection on user-active tab; scoped but broad in practice.
- clipboardWrite medium Can write to clipboard silently; potential data-injection vector.
- downloads medium Can trigger file downloads without explicit user file-picker.
- scripting high Programmatic script injection into pages; high capability when paired with <all_urls>.
- <all_urls> (host_permission) high Grants content script and scripting API access to every site visited.
Pillar Scores
Permissions5.50
Reputation4.00
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssiedn648b98fbdp727562726963xsx | 4.34 | Medium | review | 2026-09-07 |
| sssiedn0d33bf5ddp727562726963xsx | 4.01 | Medium | review | 2026-08-26 |
| <fsssiedx{$"sssiedx | 4.77 | Medium | review | 2026-08-20 |
| <fsssiedxh"sssiedx | 4.28 | Medium | review | 2026-08-20 |
| <fsssiedxh$"sssiedx | 4.30 | Medium | review | 2026-08-20 |
| xx pfsssiedxm<sssiedx | 4.24 | Medium | review | 2026-08-20 |
| %22fsssiedxmfdsaxax><!--></ScRiPt>asddsssiedx | 4.56 | Medium | review | 2026-08-20 |
| %27fsssiedxm"sssiedx | 4.47 | Medium | review | 2026-08-20 |
| 'fsssiedxm'sssiedx | 4.28 | Medium | review | 2026-08-20 |
| 4.52 | Medium | review | 2026-08-20 | |
| fsssiedxm$"sssiedx | 4.31 | Medium | review | 2026-08-20 |
| <fsssiedxi"sssiedx | 4.04 | Medium | review | 2026-07-28 |
| <fsssiedxi$"sssiedx | 2.95 | Low | review | 2026-07-28 |
| fsssiedx<sssiedx | 4.01 | Medium | review | 2026-07-28 |
| fsssiedxa"sssiedx | 4.12 | Medium | review | 2026-07-28 |
| fsssiedxa$'sssiedx | 4.05 | Medium | review | 2026-07-28 |
| fsssiedxa$"sssiedx | 4.18 | Medium | review | 2026-07-28 |
| sssieddrubricxsx | 4.35 | Medium | review | 2026-07-28 |
| v3.6 | 4.46 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA
907472dfc094…
Force block
— not fired
Score recovered
no
Elapsed
24.6s