MerchFlow for Merch by Amazon
oljoghgilhcjjknmahegnfjipfibhlap
Risk Score
3.46
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Brand impersonation: extension references 'amazon' but developer is not Amazon (confirmed_owner=false, is_impersonation=true).
- declarativeNetRequestWithHostAccess + broad Amazon host_permissions enables request interception on Amazon sessions.
- jQuery 1.12.4 bundled with 4 medium-severity CVEs (XSS) — well below fixed versions 3.4.0/3.5.0.
- Dynamic script creation in vulnerable jQuery file increases XSS exploitability risk.
- No developer name listed; gumroad.com host access expands surface beyond stated Amazon dashboard function.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'amazon'; confirmed_owner=false; developer is not Amazon.
- cve_jquery_medium_x4 crx jquery@1.12.4 has 4 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); fixed in 3.5.0.
- declarativeNetRequestWithHostAccess manifest HIGH-tier permission paired with broad Amazon host_permissions allows network-level interception.
- verified_publisher store verified_publisher=true; domain merchflow.app resolves; mitigates some reputation risk.
- privacy_policy_scoped api Privacy policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
- js_external_hosts_diverse crx 12 external hosts including posthog.com (analytics), sentry.io, gumroad.com, yandex.com.
- script_src_dynamic_in_vuln_jquery crx Dynamic <script> injection pattern found in jquery@1.12.4 with known XSS CVEs — amplifies exploitability.
- no_developer_name store developer_name is empty string; reduces accountability signal.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.12.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.12.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Local data persistence; standard for productivity tools.
- unlimitedStorage low Extended local storage; appropriate for dashboard with analytics data.
- alarms low Scheduled tasks; low standalone risk.
- offscreen low Background DOM processing; moderate but no network exfil indicator.
- declarativeNetRequestWithHostAccess high Can intercept/modify network requests on declared host_permissions (Amazon domains).
- *://*.amazon.com/* (host) high Full access to amazon.com pages including session cookies and DOM.
- *://*.gumroad.com/* (host) medium Access to payment/licensing platform; scope beyond core Amazon function.
- *://*.sentry.io/* (host) low Error reporting endpoint; known telemetry provider.
- *://*.merchflow.app/* (host) low Developer's own domain; expected for backend API calls.
Pillar Scores
Permissions4.50
Reputation5.00
Network3.50
Webstore3.50
Maintenance0.00
Privacy1.00
Code Quality3.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA
f95d8a5250b5…
Force block
— not fired
Score recovered
no
Elapsed
31.1s