Is "Amazon Order Exporter" on Chrome Web Store Safe to Install?
Export your entire Amazon order history to Excel (.xlsx) or CSV in just a few clicks — completely free, forever. What it does Amazon Order Exporter scans your order history and downloads a clean spreadsheet with everything you need: order date, order number, item name, price, order total, quantity, seller, condition, and direct links to every item and order. Key features • Export one year or multiple years at once • Excel export with proper number formatting for prices and clickable hyperlinks • CSV export compatible with Excel, Google Sheets, and any spreadsheet app • Scheduled auto-exports — set it to run daily, weekly, or monthly automatically • Works across all major Amazon storefronts: .com, .co.uk, .ca, .com.au, .de, .fr, .es, .it, .co.jp, .in, .com.mx, .com.br • No account, no sign-up, no data ever leaves your browser Privacy This extension only reads your Amazon order pages while you are logged in. No data is collected, stored, or sent to any external server. Everything happens locally in your browser. Support This extension is free forever. If it saves you time, consider supporting development on Ko-fi. Questions? Reach us at [email protected]
Risk Assessment
Analyzed2 security findings detected across all analyzers
Chrome extension requesting 19 permissions
Severity Breakdown
Finding Categories
Requested Permissions
19 permissionsManage, modify, and monitor downloads
About This Extension
Detailed Findings
2 totalAI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-27. The review verdict is likely false positive with 85% confidence.
Recommended action: suppress false positive.
Risk context: MEDIUM risk, score 63/100.
Evidence context: threat category none; evidence quality strong.
This extension presents as an Amazon order history exporter with findings that align with its stated functionality. The 54 IoC findings are entirely benign: domains like https://www.amazon.com/*, https://www.amazon.co.uk/*, and https://www.amazon.ca/* match the extension's declared purpose of accessing Amazon order pages. The http://schemas.openxmlformats.org/ URLs are standard OpenXML namespace identifiers required for Excel file generation, not network endpoints. The https://clients2.google.com/service/update2/crx finding is Chrome's legitimate extension update endpoint.
The 19 code-smell findings fall into the known false-positive category per CVEQ documentation. Rules like postinstall_* and credential_* fire on basic JavaScript patterns (fetch, API references) and should not drive verdicts. Critically, there are zero malware signatures and zero obfuscation findings, which are the strongest indicators of actual malicious intent.
The developer identity ([email protected]) is a generic Gmail address rather than a verified publisher, which is a minor concern. However, this alone does not indicate malicious behavior—many legitimate developers use personal email addresses. The extension has 0 users, suggesting it may be new or niche rather than widely distributed malware.
Counterargument: A skeptic might argue that the 75 total findings and anonymous developer warrant caution. However, finding COUNT is explicitly documented as meaningless in CVEQ's known false-positive patterns. The NATURE of these findings matters: all IoCs are either legitimate Amazon domains (matching the extension's purpose) or standard XML namespaces for Excel export. There are no suspicious third-party domains, no credential theft patterns, no browser hijacking indicators, and no malware signatures. The code-smell findings are classified as severity: low and finding_type: code-smell, which the threat model explicitly states should NEVER drive a verdict.
This extension exhibits the classic false-positive profile: high finding volume driven by legitimate functionality (Amazon access + Excel export) triggering generic rules. Without malware signatures, obfuscation, or suspicious domains, there is no evidence of malicious intent.
Key Reasons
- All IoCs are legitimate Amazon domains matching extension purpose
- Zero malware signatures detected
- Zero obfuscation findings
- OpenXML namespace URLs are standard for Excel export functionality
- Code-smell findings are known false positives per CVEQ documentation
False Positive Considerations
- OpenXML namespace URLs flagged as suspicious domains
- Code-smell rules firing on standard JavaScript patterns
- Legitimate Amazon domains matching extension functionality
- Google Chrome update endpoint flagged as IoC
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Ship Xanh copy sản phẩm, nhân bản shop, hiển thị % phí sàn, lượt bán tháng
[email protected]
SVG to AVIF Converter [ShiftShift]
[email protected]
ChromeCompare
[email protected]
CAI Tools
[email protected]
Auto Gmail - ChatGPT AI for email inbox
[email protected]
EC Seller Tools
[email protected]