Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MerchFlow for Merch by Amazon

oljoghgilhcjjknmahegnfjipfibhlap
Risk Score
3.46
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 3,000
Rating 4.8
Last updated 2026-06-15
Manifest version MV3
CSP present ✅ yes
Developer hello@merchflow.app
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension references 'amazon' but developer is not Amazon (confirmed_owner=false, is_impersonation=true).
  • declarativeNetRequestWithHostAccess + broad Amazon host_permissions enables request interception on Amazon sessions.
  • jQuery 1.12.4 bundled with 4 medium-severity CVEs (XSS) — well below fixed versions 3.4.0/3.5.0.
  • Dynamic script creation in vulnerable jQuery file increases XSS exploitability risk.
  • No developer name listed; gumroad.com host access expands surface beyond stated Amazon dashboard function.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'amazon'; confirmed_owner=false; developer is not Amazon.
  • cve_jquery_medium_x4 crx jquery@1.12.4 has 4 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); fixed in 3.5.0.
  • declarativeNetRequestWithHostAccess manifest HIGH-tier permission paired with broad Amazon host_permissions allows network-level interception.
  • verified_publisher store verified_publisher=true; domain merchflow.app resolves; mitigates some reputation risk.
  • privacy_policy_scoped api Privacy policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
  • js_external_hosts_diverse crx 12 external hosts including posthog.com (analytics), sentry.io, gumroad.com, yandex.com.
  • script_src_dynamic_in_vuln_jquery crx Dynamic <script> injection pattern found in jquery@1.12.4 with known XSS CVEs — amplifies exploitability.
  • no_developer_name store developer_name is empty string; reduces accountability signal.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.12.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.12.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Local data persistence; standard for productivity tools.
  • unlimitedStorage low Extended local storage; appropriate for dashboard with analytics data.
  • alarms low Scheduled tasks; low standalone risk.
  • offscreen low Background DOM processing; moderate but no network exfil indicator.
  • declarativeNetRequestWithHostAccess high Can intercept/modify network requests on declared host_permissions (Amazon domains).
  • *://*.amazon.com/* (host) high Full access to amazon.com pages including session cookies and DOM.
  • *://*.gumroad.com/* (host) medium Access to payment/licensing platform; scope beyond core Amazon function.
  • *://*.sentry.io/* (host) low Error reporting endpoint; known telemetry provider.
  • *://*.merchflow.app/* (host) low Developer's own domain; expected for backend API calls.

Pillar Scores

Permissions4.50
Reputation5.00
Network3.50
Webstore3.50
Maintenance0.00
Privacy1.00
Code Quality3.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA f95d8a5250b5…
Force block — not fired
Score recovered no
Elapsed 31.1s