Share-A-Cart for Amazon
peiobddfomnijgoblelfdmjblplojcoe
Risk Score
4.00
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies permission + scripting on 18 Amazon storefronts — can read session tokens and inject code into Amazon pages
- No CSP declared; 5 innerHTML DOM-XSS sinks across popup/receive_cart/options with no sanitization boundary
- 4 sibling extensions under same operator fingerprint — elevated operator surface area and potential pivot risk
- Brand impersonation flag: 'amazon' mentioned without confirmed ownership; not a verified publisher
- Privacy policy discloses third-party sharing but lacks data retention schedule; cookies on Amazon sessions amplifies impact
Evidence
- cookies+scripting on 18 Amazon domains manifest permissions include cookies and scripting; host_permissions cover amazon.com + 17 TLDs — full session access.
- no CSP declared crx content_security_policy is null; MV3 default applies but 5 innerHTML sinks increase XSS surface.
- 5x dom_sink_innerhtml_userctrl crx innerHTML sinks in options_page.js, popup.js, receive_cart.js, review_not_great.js, review_thanks.js.
- operator cluster: 4 siblings api Same dev email shares fingerprint with 4 other extension IDs; compound cluster match.
- brand_mention impersonation store brands_mentioned=[amazon], confirmed_owner=false, is_impersonation=true; not verified or featured-verified.
- no developer name in manifest manifest developer_name is empty string; reduces accountability signal.
- privacy policy: third_party_sharing true, retention false api Policy scoped to extension and admits data collection + 3rd-party sharing but no retention period.
- unexpected host: crtsh.net manifest host_permissions includes https://crtsh.net/* with no stated functional justification.
Permissions Breakdown
- alarms low Schedules background tasks; minimal direct data risk.
- clipboardWrite medium Can write to clipboard; useful for sharing cart links but can be abused.
- storage low Local extension data storage; low risk in isolation.
- unlimitedStorage low Allows large local storage; could store scraped cart data indefinitely.
- tabs medium Can read tab URLs and titles; moderate tracking potential.
- cookies high Can read Amazon session cookies across all scoped Amazon domains — high exfil risk.
- activeTab low Limits page access to user-activated tab only; mitigates some scripting risk.
- scripting high Programmatic script injection into Amazon pages; broad capability when paired with host_permissions.
- host:https://www.amazon.com/* (and 17 other Amazon TLDs) high Full Amazon session access across 18 storefronts; cookies+scripting combo is high risk.
- host:https://www.share-a-cart.com/* low Dev's own domain; expected for cart-sharing backend.
- host:https://crtsh.net/* medium Unexpected third-party domain access; no clear functional need stated.
Pillar Scores
Permissions5.50
Reputation5.50
Network2.50
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00
Operator Siblings (4)
Other extensions sharing this developer's compound fingerprint:
Scoring History
| v3.6 | 4.00 | Medium | review | 2026-06-16 |
| v3.4-rev | 4.08 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA
f17e2ccdadd3…
Force block
— not fired
Score recovered
no
Elapsed
36.6s