Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Share-A-Cart for Amazon

peiobddfomnijgoblelfdmjblplojcoe
Risk Score
4.00
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 40,000
Rating 4.5
Last updated 2026-04-21 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@share-a-cart.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies permission + scripting on 18 Amazon storefronts — can read session tokens and inject code into Amazon pages
  • No CSP declared; 5 innerHTML DOM-XSS sinks across popup/receive_cart/options with no sanitization boundary
  • 4 sibling extensions under same operator fingerprint — elevated operator surface area and potential pivot risk
  • Brand impersonation flag: 'amazon' mentioned without confirmed ownership; not a verified publisher
  • Privacy policy discloses third-party sharing but lacks data retention schedule; cookies on Amazon sessions amplifies impact

Evidence

  • cookies+scripting on 18 Amazon domains manifest permissions include cookies and scripting; host_permissions cover amazon.com + 17 TLDs — full session access.
  • no CSP declared crx content_security_policy is null; MV3 default applies but 5 innerHTML sinks increase XSS surface.
  • 5x dom_sink_innerhtml_userctrl crx innerHTML sinks in options_page.js, popup.js, receive_cart.js, review_not_great.js, review_thanks.js.
  • operator cluster: 4 siblings api Same dev email shares fingerprint with 4 other extension IDs; compound cluster match.
  • brand_mention impersonation store brands_mentioned=[amazon], confirmed_owner=false, is_impersonation=true; not verified or featured-verified.
  • no developer name in manifest manifest developer_name is empty string; reduces accountability signal.
  • privacy policy: third_party_sharing true, retention false api Policy scoped to extension and admits data collection + 3rd-party sharing but no retention period.
  • unexpected host: crtsh.net manifest host_permissions includes https://crtsh.net/* with no stated functional justification.

Permissions Breakdown

  • alarms low Schedules background tasks; minimal direct data risk.
  • clipboardWrite medium Can write to clipboard; useful for sharing cart links but can be abused.
  • storage low Local extension data storage; low risk in isolation.
  • unlimitedStorage low Allows large local storage; could store scraped cart data indefinitely.
  • tabs medium Can read tab URLs and titles; moderate tracking potential.
  • cookies high Can read Amazon session cookies across all scoped Amazon domains — high exfil risk.
  • activeTab low Limits page access to user-activated tab only; mitigates some scripting risk.
  • scripting high Programmatic script injection into Amazon pages; broad capability when paired with host_permissions.
  • host:https://www.amazon.com/* (and 17 other Amazon TLDs) high Full Amazon session access across 18 storefronts; cookies+scripting combo is high risk.
  • host:https://www.share-a-cart.com/* low Dev's own domain; expected for cart-sharing backend.
  • host:https://crtsh.net/* medium Unexpected third-party domain access; no clear functional need stated.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.50
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00

Operator Siblings (4)

Other extensions sharing this developer's compound fingerprint:

Scoring History

v3.6 4.00 Medium review 2026-06-16
v3.4-rev 4.08 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA f17e2ccdadd3…
Force block — not fired
Score recovered no
Elapsed 36.6s