Crazy Freekick
bbjdlbemjklojnbifkgameepcafflmem
Risk Score
4.50
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack flag set — extension registers an uninstall callback to a 3rd-party URL
- Install URL hijack opens popup/index.html on install — potential onboarding abuse
- Three medium CVEs in bundled jquery@3.2.1 (XSS); version below fixed_in 3.5.0
- Privacy policy hosted on cdn.cloudapi.stream, scope_extension=false; mentions 3rd-party sharing without scoping to this extension
- Free-webmail dev (gmail) with no developer name and no business website — low accountability
Evidence
- uninstall_url_hijack crx uninstall_url_hijack=true; target null but flag set — extension hooks chrome.runtime.setUninstallURL to 3rd party.
- install_url_hijack crx install_url_hijack=true; target popup/index.html — onInstalled fires navigation.
- jquery_cve_trio crx jquery@3.2.1 bundled with CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all medium, fixed in 3.5.0).
- privacy_policy_generic store Policy at cdn.cloudapi.stream: scope_extension=false, data_collection=false, third_party_sharing=true — generic, not extension-scoped.
- free_webmail_no_devname store Developer email nadejdinv@gmail.com; developer_name empty; no business website — minimal accountability.
- sandbox_csp_unsafe manifest Sandbox CSP includes unsafe-inline and unsafe-eval on script-src — elevated XSS risk in sandbox context.
- 10_external_js_hosts crx 10 external JS hosts referenced (createjs.com, goo.gl, cloudapi.stream, etc.); broad external dependency surface.
- low_install_count store Only 56 installs; no verified publisher; no featured badge — negligible trust signals.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Pillar Scores
Permissions0.00
Reputation7.00
Network0.00
Webstore9.00
Maintenance1.50
Privacy9.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:27
Listing SHA
b36183ad1b71…
Force block
— not fired
Score recovered
no
Elapsed
—