Chrome Web Store Verified

Ship Xanh copy sản phẩm, nhân bản shop, hiển thị % phí sàn, lượt bán tháng

by [email protected] · 20.0K users · 5.0 rating
00005ce4-9ed8-56c3-b7a5-245f58d06ec3 | v3.2.62
53/ 100
MEDIUM risk
No change since v3.2.61
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (53/100) still counts them.

Analysis record

Analysed
3 days ago
Version
v3.2.62
Artifact
SHA256 C1C…A41
Source
Findings (non-IoC)

Is Ship Xanh copy sản phẩm, nhân bản shop, hiển thị % phí sàn, lượt bán tháng safe?

The listing describes product copying and shop-management tools for marketplaces such as Shopee and Lazada. This extension declares no special permissions, and the supplied endpoint list is empty. Its bundled code still contains fetch activity in assets/chunk-3cfb730f.js:1:0 and assets/chunk-ea756fd5.js:3:0, plus Socket.IO activity in assets/chunk-77e9fb52.js:38:0 and :40:0, so the app can exchange data with a service even though no destination is named.

The finding titles NET-FETCH-assets/chunk-3cfb730f.js-1 and NET-SOCKET_IO-assets/chunk-77e9fb52.js-38 describe network functions. If those calls reached a harmful or unexpected service, the missing endpoint details would make that hard to see from this page. The listed paths contain no malware signature, obfuscation finding, credential-theft indicator, or suspicious domain finding.

The scanner was triggered by common fetch and Socket.IO code in the bundled files, which fits the product and shop features named in the listing. With no special permissions, no named endpoints, and no malware-related match tied to assets/chunk-3cfb730f.js:1:0, assets/chunk-ea756fd5.js:3:0, or assets/chunk-77e9fb52.js:38:0, the recorded alerts do not show harmful behavior.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1 detail row

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

43
Noisy-finding weight
x1.00
Publisher domain
shipxanh.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

Requested Permissions

7 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
webRequest

Intercept, modify, and block all network requests

High
tabs
Medium
activeTab
Medium
sidePanel
Low
storage
Low
scripting
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The extension listing describes tools for copying products and managing shops across Shopee, TikTok, Lazada, 1688, and Taobao. The code paths tied to the findings are assets/chunk-3cfb730f.js:1:0, assets/chunk-ea756fd5.js:3:0, and assets/chunk-77e9fb52.js:38:0 through :40:0. Their titles identify fetch and Socket.IO activity, which fits a web tool that exchanges product, stock, order, or shop data with a service. The supplied endpoint list is empty, so these findings identify network behavior without naming a destination domain.

The strongest signal in the supplied material is NET-SOCKET_IO-assets/chunk-77e9fb52.js-38 and NET-SOCKET_IO-assets/chunk-77e9fb52.js-40. Socket.IO supports persistent client-server updates, which can fit live inventory or order status features described by the listing. NET-FETCH-assets/chunk-3cfb730f.js-1 and NET-FETCH-assets/chunk-ea756fd5.js-3 identify ordinary request code in bundled JavaScript. These titles do not identify credential collection, cookie access, search replacement, injected advertising, proxy routing, or data sent to a suspicious domain.

The absence of a destination domain limits what can be confirmed about the network calls. Still, the listed paths contain no IoC finding, malware signature, obfuscation finding, secret finding, or tool-poisoning finding. assets/chunk-3cfb730f.js:1:0, assets/chunk-ea756fd5.js:3:0, and assets/chunk-77e9fb52.js:38:0 therefore provide evidence of application communications, rather than evidence of a harmful payload. The empty permissions list also gives the extension no declared special browser permission in the supplied metadata.

A skeptic could argue that Socket.IO activity in assets/chunk-77e9fb52.js:38:0 and :40:0 might support hidden tracking or remote control. That concern cannot be resolved from these titles alone because the endpoint list is empty and the finding descriptions contain no destination or payload detail. It also lacks support from the other recorded indicators: NET-FETCH-assets/chunk-3cfb730f.js-1 and NET-FETCH-assets/chunk-ea756fd5.js-3 are generic fetch detections, while no IoC, malware, obfuscation, or secret finding is recorded. Runtime URL inspection would be needed to establish a harmful destination.

The available evidence therefore supports treating these findings as bundled application network behavior. The remaining uncertainty comes from the missing endpoint details, rather than from a concrete malicious indicator in the cited files.

Key Reasons

  • NET-FETCH-assets/chunk-3cfb730f.js-1 and NET-FETCH-assets/chunk-ea756fd5.js-3 identify generic fetch code in bundled application files.
  • NET-SOCKET_IO-assets/chunk-77e9fb52.js-38 and NET-SOCKET_IO-assets/chunk-77e9fb52.js-40 fit live shop or inventory communication.
  • The supplied endpoint list and permissions list are empty.
  • No malware, obfuscation, IoC, secret, or tool-poisoning finding is tied to the cited paths.

False Positive Considerations

  • Generic fetch detections in assets/chunk-3cfb730f.js:1:0 and assets/chunk-ea756fd5.js:3:0.
  • Socket.IO detections in bundled code at assets/chunk-77e9fb52.js:38:0 and :40:0.
  • The network endpoint list is empty, so the scanner supplies no suspicious destination domain.
  • No malware or obfuscation finding is associated with the cited JavaScript paths.

Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 88%.

Chrome version history

Risk trend by version

10 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
53
Change since first
-4
Change from previous
No change
Versions:
First analyzed version
3.2.40
Jan 21, 2026
Risk range
53 to 58
Across analyzed versions
Latest analyzed version
3.2.62
Sep 28, 2026
Selected version
medium
Version
v3.2.62
3 days ago
Risk score
53
Findings
5
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

A. Copy sản phẩm, nhân bản shop => Ví dụ copy sản phẩm từ Shopee sang Tikok; sao chép sản phẩm của đối thủ; copy sản phẩm từ shop bị khóa; copy sản phẩm từ nguồn hàng 1688, Taobao, Aliexpress… Có hỗ trợ dịch đa ngôn ngữ => Có chèn logo, khung ảnh ở bước đăng sản phẩm nên vẫn giữ được ảnh gốc => Có ChatGPT hỗ trợ viết lại tên sản phẩm, viết lại mô tả => Có sửa sản phẩm hàng loạt trong danh sách chờ đăng => Có lập lịch đăng lên fanpage miễn phí, tự động spin content. Tự lắp ghép content B. Hiển thị % phí sàn Shopee, Tiktok, Lazada => Tự động tính phí sàn ra % và hiển thị trong danh sách đơn hàng => Tự động phát hiện chênh lệch phí vận chuyển C. Xem doanh thu, lượt bán/tháng trong kết quả tìm kiếm sản phẩm Shopee => Hiển thị thống kê lượt bán/tháng, doanh thu tháng => Xem thời gian sản phẩm được đăng => Xem lượt đánh giá, điểm đánh giá của sản phẩm => Xem lượt bán của từng biến thể (màu sắc, size..) D. Quản lý đơn hàng đa kênh, theo dõi đơn hoàn => Tự động đồng bộ đơn từ Shopee, Tiktok, Lazada, POS => Tính năng đóng gói đơn hàng loạt, tăng tốc độ vận hành => Tự động phát hiện đơn hàng hoàn mà shop chưa nhận được => Tự động phát hiện đơn hàng bị hủy mặc dù thực tế đã giao cho bên vận chuyển => Tự động thông báo đơn hỏa tốc, thông báo đơn hỏa tốc đã giao, đã hủy. E. Đồng bộ tồn kho đa kênh => AI Ship Xanh tự động phát hiện đơn hàng chưa liên kết tồn kho ở bước chuẩn bị giao hàng => Gợi ý liên kết tồn kho bằng trí tuệ nhân tạo AI, siêu nhanh => Dùng ngay mà không cần kiểm toàn bộ kho, không cần liên kết đủ các shop, AI Ship Xanh tự động nhắc bạn liên kết tồn kho cho những đơn hàng mới F. Tính năng khác => Đóng dấu tuỳ ý lên mỗi đơn hàng từ sàn TMĐT trước khi in => Tải về máy tính video sản phẩm, ảnh sản phẩm từ các sàn hoặc nguồn bất kỳ => Lưu lại toàn bộ sản phẩm Shopee, Lazada để backup sau này tái sử dụng Chúng tôi đủ năng lực giúp bạn thay thế phần mềm quản lý bán hàng bạn đang dùng bằng phần mềm Ship Xanh tốt hơn. Chúng tôi bổ sung tính năng mới liên tục hàng tuần, cùng các chuyên gia trong lĩnh vực trí tuệ nhân tạo AI đến từ team Ship Xanh, việc ứng dụng Ship Xanh vào vận hành kinh doanh sẽ giúp bạn không nép vế trước đối thủ Đừng ngại liên hệ team 24/7 khi bạn gặp bất kỳ trở ngại nào Hotline Zalo, Whatsapp, Telegram: +84387976660 +84328803015 https://www.facebook.com/phanmemshipxanh https://youtube.com/shipxanh

Frequently Asked Questions