Share-A-Cart for Walmart
pmmodpeofmnekbdbjojhidofleeacmij
Risk Score
3.56
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- cookies permission over *.walmart.com allows session token access if extension is compromised.
- 5 innerHTML DOM-XSS sinks across multiple JS files with no CSP; cart data from shared carts could trigger XSS.
- Operator cluster of 4 sibling extensions under same dev email increases supply-chain risk surface.
- Privacy policy admits third-party data sharing but lacks retention disclosure.
- No developer name listed; reduced accountability.
Evidence
- cookies+scripting on *.walmart.com without CSP manifest cookies and scripting permissions paired with broad Walmart host; no content_security_policy set.
- 5 innerHTML sinks, no CSP — elevated DOM-XSS risk (v3 FIX B applies) crx dom_sink_innerhtml_userctrl in 5 files; csp_present==false triggers +2.0 code-quality uplift per FIX B.
- operator_cluster sibling_count=4 api 4 sibling extensions share same dev email fingerprint; +2.5 webstore signal applied.
- privacy policy: third_party_sharing=true, retention=false, scope_extension=true api Policy scoped but admits 3rd-party sharing without retention; scored +1.0+1.0 privacy.
- featured_by_google=true, no verified_publisher badge store Google Featured badge provides partial trust signal; -2.0 reputation discount applied.
- js_external_hosts includes 12 retail domains beyond stated Walmart scope crx Hosts like img.abercrombie.com, reactjs.org etc. suggest multi-retailer sibling code base.
- no developer name store developer_name is empty; +1.0 reputation penalty applied.
- cve_findings_raw empty; no CVEs detected crx No CVE findings; CVE pillar = 0.0.
Permissions Breakdown
- alarms low Schedule background tasks; minimal risk.
- clipboardWrite medium Can write to clipboard; could be used to push unexpected content.
- storage low Local data persistence; low risk in isolation.
- unlimitedStorage low Allows large local storage; minimal direct risk.
- tabs medium Access to tab URLs and metadata across sessions.
- cookies high Can read/write cookies; scoped to declared hosts (walmart.com, share-a-cart.com).
- activeTab low Transient access to current tab on user gesture.
- scripting medium Can inject scripts into pages; risk bounded by host_permissions scope.
- https://share-a-cart.com/* low Developer-owned domain; expected for cart sync.
- https://crtsh.net/* low Unusual for a shopping extension; low observed risk.
- https://*.walmart.com/* medium Broad Walmart subdomain access; cookies+scripting here is core function.
Pillar Scores
Permissions5.00
Reputation4.00
Network2.50
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00
Operator Siblings (4)
Other extensions sharing this developer's compound fingerprint:
Scoring History
| v3.6 | 3.56 | Low | review | 2026-06-16 |
| v3.4-rev | 3.08 | Low | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA
5d2c9a3f3801…
Force block
— not fired
Score recovered
no
Elapsed
31.3s