芒果店长
ID: imjfokfjjgpijjfgnodojafbkoonmmkh
Supported Languages
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- 富通天下云技术团队View Profile
- Privacy
- Privacy Policy
- MX records exist
- Yes
- Domain exists
- Yes
- Is disposable
- Yes
- Is role-based
- No
- Mailbox exists
- Yes
芒果店长产品采集插件,支持单品和分类采集。
芒果店长(http://www.mangoerp.com/)产品采集工具,支持单品采集和分类采集。采集后可发布到多平台多店铺。
Item | Type | Severity | Description |
|---|---|---|---|
| scripting | Permission | Critical | This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to. |
| webRequest | Permission | Critical | This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens. |
| declarativeNetRequest | Permission | Critical | This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites. |
| http://*/* | Host | Critical | Broad host access — the extension can read/modify content on every website. |
| https://*/* | Host | Critical | Broad host access — the extension can read/modify content on every website. |
| cookies | Permission | High | This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites. |
| nativeMessaging | Permission | High | This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files. |
| Dangerous Permission Combination: scripting,cookies,webRequest | Risk Factor | High | Enables extensions to interact with scripts, modify files and downloads, and alter browsing history and bookmarks, potentially affecting data integrity and user control. |
| Contextual Risk Factors | Risk Factor | High | The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact |
| tabs | Permission | Medium | This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns. |
| storage | Permission | Medium | This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads. |
| http://*.mangoerp.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.mangoerp.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.alicdn.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.alicdn.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.taobaocdn.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.taobaocdn.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.aliexpress.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.aliexpress.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.dhgate.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.1688.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.1688.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.taobao.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.taobao.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.tmall.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.tmall.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.etsy.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.ebay.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.ebay.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.ebaydesc.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.amazon.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.amazon.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.wish.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.jd.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.jd.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.jd.hk/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.jd.hk/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.banggood.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.banggood.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.dhgate.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.jumia.com.ng/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.jumia.com.ng/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.alibaba.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.alibaba.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.17zwd.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.17zwd.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.kilimall.co.ug/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.kilimall.co.ug/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.lazada.com.my/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.lazada.com.my/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.lazada.co.id/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.lazada.co.id/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.lazada.com.ph/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.lazada.com.ph/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.lazada.sg/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.lazada.sg/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.lazada.com.th/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.lazada.com.th/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.lazada.vn/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.lazada.vn/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.pfhoo.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.pfhoo.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://shopee.com.my/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://shopee.com.my/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://shopee.co.id/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://shopee.co.id/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://shopee.ph/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://shopee.ph/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://shopee.sg/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://shopee.sg/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://shopee.co.th/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://shopee.co.th/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://shopee.vn/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://shopee.vn/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://www.wsy.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://www.wsy.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.sooxie.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.sooxie.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://p.3.cn/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://d.3.cn/ | Host | Medium | Host permission — access limited to this URL pattern. |
| https://*.designkit.cn/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.designkit.cn/ | Host | Medium | Host permission — access limited to this URL pattern. |
| http://*.tiktok.com/ | Host | Medium | Host permission — access limited to this URL pattern. |
| Access to Sensitive Domains | Risk Factor | Medium | This extension requests access to sensitive domains: http://www.ebay.com/, https://www.ebay.com/, http://*.ebaydesc.com/, http://www.amazon.com/, https://www.amazon.com/ |
| contextMenus | Permission | Low | This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content. |
Sensitive Domain Access
This extension has access to the following sensitive domains:
- http://www.ebay.com/
- https://www.ebay.com/
- http://*.ebaydesc.com/
- http://www.amazon.com/
- https://www.amazon.com/
By severity
Versions scanned
Showing 1 of 61 scanned versions with more than one unique finding. Counts are unique findings that include each version.
| Extension Version | Code Review Findings |
|---|---|
| 2.0.3 | 3 |
Files with findings
3 distinct paths — top paths by unique finding count:
- background.js1
- content.js1
- manifest.json1
S.No. | Category | Severity | File | Summary | Found in Version |
|---|---|---|---|---|---|
| 1 | Remote Code Loading | high | content.js (line 1069) | On every page load the content script calls fetch.mangoerp.com/parse/identify?url=<page_url> and, if the server returns a 'detect' field, immediately sends it to background.js via the 'execute' message. Background.js … | |
| 2 | Remote Code Loading | high | background.js (line 157) | The h() helper is injected into every target tab via chrome.scripting.executeScript and evaluates server-provided strings using eval5.Function. The three dispatch modes (localhref, element, url) all evaluate code stri… | |
| 3 | Other | medium | manifest.json (line 46) | The bundled manifest grants externally_connectable messaging rights and web_accessible_resources exposure to five additional origins (MercadoLibre country variants, TikTok) beyond the single *://*.mangoerp.com/* shown… |
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
Gain full insight into all external connections.
Upgrade for full visibility.
| errors.angularjs.org | /1.3.0-rc.2/ | http://errors.angularjs.org/1.3.0-rc.2/ |
| commimg.pddpic.com | /mms_static/75be7914c267253ea82574a998ba9d5b.eot | https://commimg.pddpic.com/mms_static/75be7914c267253ea82574a998ba9d5b.eot |
| commimg.pddpic.com | /mms_static/f536b2f15e5431ab8643cf2e0cf9b671.woff | https://commimg.pddpic.com/mms_static/f536b2f15e5431ab8643cf2e0cf9b671.woff |
| commimg.pddpic.com | /mms_static/4e88b5912f33dbfcc377716e06cfc0ae.ttf | https://commimg.pddpic.com/mms_static/4e88b5912f33dbfcc377716e06cfc0ae.ttf |
| commimg.pddpic.com | /mms_static/f96e65cc45bca9197b873271484a8346.svg | https://commimg.pddpic.com/mms_static/f96e65cc45bca9197b873271484a8346.svg |
| funimg.pddpic.com | /c39d2d55-073f-4c79-adfa-71811fd3de39.png.slim.png | https://funimg.pddpic.com/c39d2d55-073f-4c79-adfa-71811fd3de39.png.slim.png |
| funimg.pddpic.com | /9ebfff6f-be47-4180-8d35-e40d4338ff93.png.slim.png | https://funimg.pddpic.com/9ebfff6f-be47-4180-8d35-e40d4338ff93.png.slim.png |
| funimg.pddpic.com | /1d74730d-555e-492c-a6eb-666b58d54689.png.slim.png | https://funimg.pddpic.com/1d74730d-555e-492c-a6eb-666b58d54689.png.slim.png |
| funimg.pddpic.com | /31a1b545-c230-4bc1-9068-d01a70c8bf1b.png.slim.png | https://funimg.pddpic.com/31a1b545-c230-4bc1-9068-d01a70c8bf1b.png.slim.png |
| funimg.pddpic.com | /b551d85c-0467-4bb6-ad75-cce23e397c54.png.slim.png | https://funimg.pddpic.com/b551d85c-0467-4bb6-ad75-cce23e397c54.png.slim.png |
Gain full insight into all external connections.
Upgrade for full visibility.
| 127.0.0.1 | IPv4 | - |
Version | Size | Is Malicious | Findings | Permhash |
|---|---|---|---|---|
2.0.6 Latest | 1.91 MB | Benign | — | |
2.0.5 | 1.91 MB | Benign | — | |
2.0.4 | 1.91 MB | Benign | — | |
2.0.3 | 1.91 MB | Malicious | 3 | |
2.0.2 | 1.90 MB | Benign | — | |
2.0.1 | 1.90 MB | Benign | — | |
1.9.8 | 1.90 MB | Benign | — | |
1.9.7 | 1.90 MB | Benign | — | |
1.9.6 | 1.90 MB | Benign | — | |
1.9.4 | 1.90 MB | Benign | — |
Code Diff
Compare extension code between any two versions.
No comparable text files found between these versions.
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.