Rooftop Snipers Funny Game
amoilkdbdljhjepahbkimfapimcifinp
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack and install URL hijack both present — classic traffic-monetization shell pattern.
- Privacy policy URL returns SSL error (fetched=false) — treated as no policy (+10.0 privacy).
- Free-webmail developer email (gmail), no developer name, no verified publisher — minimal accountability.
- 31 months since last update — effectively abandoned extension still live in store.
- new Function() constructor found in game JS — dynamic code execution risk.
Evidence
- uninstall_url_hijack + install_url_hijack crx Both hijacks present; install redirects to https://rooftopsnipers.pro/#welcome. +3.0 uninstall hijack, +2.0 install hijack.
- privacy_policy_fetch_failed api SSLError fetching https://rooftopsnipers.pro/privacy-policy — classified as fetched=false → +10.0 privacy.
- free_webmail_no_dev_name store Dev email andienhuynhngoc01@gmail.com, developer_name empty, no verified publisher → reputation floor 7.5.
- stale_extension store 31 months since last update → maintenance +8.5.
- function_constructor crx new Function() in Game/js/gadget.config.js — dynamic code execution via user-controlled or config string.
- sandbox_unsafe_eval manifest CSP sandbox page allows unsafe-eval, unsafe-inline, blob: — weakened sandbox isolation.
- js_external_hosts crx Extension references csi.gstatic.com, gg.google.com, github.com, rooftopsnipers.pro — 4 external hosts but no bad-host hits.
- no_permissions_but_hijacks crx Zero declared permissions/host_permissions yet both install/uninstall URL hijacks present — shell pattern.
Pillar Scores
Permissions0.00
Reputation7.50
Network0.00
Webstore9.00
Maintenance8.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 05:14
Listing SHA
6a263230b2b5…
Force block
— not fired
Score recovered
no
Elapsed
—