Track Package
onjnkdhpnecgfhnplplfidpjbalmppoo
Risk Score
5.78
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits 3rd-party sharing but not scoped to this extension — effectively a generic data-collection policy.
- Uninstall and install URL hijacks detected — classic traffic-monetization shell pattern.
- Content script on <all_urls> paired with 9 external JS hosts including s1search.co and aakkgo.com.
- jquery@3.3.1 carries 3 medium XSS CVEs (unfixed); no CSP amplifies DOM-XSS risk.
- 19 months stale, 1-star rating, and bestfreemaps.com domain irrelevant to package tracking.
Evidence
- uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall URL callbacks set to 3rd-party destinations — monetization shell indicator.
- privacy_policy scope_extension=false, data_collection=true, third_party_sharing=true api Policy admits data collection and 3rd-party sharing without scoping to this extension → +10.0 privacy (v3.5 rule D).
- content_scripts <all_urls> manifest Broad content script injection into every site visited by user, combined with tabs permission.
- js_external_hosts suspicious domains crx Hosts include aakkgo.com, mapsm.com, www-bestfreemaps-com.s1search.co — unrelated to package tracking.
- jquery@3.3.1 CVEs crx 3 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0, bundled 3.3.1.
- no CSP + dom_sink_innerhtml_userctrl + CVEs crx innerHTML from variable in index1.js with no CSP and active jQuery XSS CVEs → elevated DOM-XSS code quality score.
- months_since_update=19, rating=1 store 19 months stale (6-12mo band but >18mo triggers 0c cap); 1-star rating signals user dissatisfaction.
- developer domain mismatch store Developer is bestfreemaps.com; privacy policy hosted on xpackage.me; extension tracks packages — brand coherence absent.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Can read tab URLs and titles across all tabs.
- activeTab low Grants access only to user-activated tab; low surface area alone.
- storage low Local key-value storage; no direct data-exfil capability.
- content_scripts:<all_urls> high Content script injected into every page; broad DOM access across all origins.
Pillar Scores
Permissions3.50
Reputation6.50
Network4.50
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality4.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 15:49
Listing SHA
a745e7798340…
Force block
— not fired
Score recovered
no
Elapsed
—