ClipKeeper - For Use with GameChanger
beelllgidjaklbnacknjkghfibfpjhac
Risk Score
3.04
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Gmail developer with no registered business name increases accountability gap.
- Uninstall and install URL hijack flags set (targets null, but hooks are present).
- innerHTML sink in content.js is a DOM-XSS risk on gc.com pages.
- new Function() in bundled jszip.min.js; CSP present mitigates but library-level risk remains.
- Privacy policy discloses third-party sharing but lacks data-retention details.
Evidence
- developer_email_free_webmail store Developer email cjessup87@gmail.com; no verified business name or domain.
- verified_publisher store Extension has verified_publisher=true, partially offsetting reputation concern.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() present; target is null so no confirmed 3rd-party redirect.
- install_url_hijack crx onInstalled URL hook present; target is null so no confirmed 3rd-party redirect.
- dom_sink_innerhtml_userctrl crx innerHTML used in content.js; CSP is present (script-src 'self') limiting exploit reach.
- function_constructor_in_jszip crx new Function() in libs/jszip.min.js; standard jszip pattern, CSP 'self' mitigates remote loading.
- privacy_policy_no_retention api Policy scoped to extension, discloses 3rd-party sharing, but retention period not specified.
- js_external_hosts_raw_github crx raw.github.com and stuk.github.io in js_external_hosts; risk of remote script dependency.
Permissions Breakdown
- storage low Standard local state storage; low risk.
- downloads medium Can trigger file downloads to user disk; appropriate for media-backup function.
- offscreen low Needed for background media processing; no direct data-access risk.
- https://web.gc.com/* low Scoped to GameChanger web app only; matches stated purpose.
- https://vod-archive.gc.com/* low Scoped to GameChanger VOD subdomain; matches video-backup function.
- https://usvlgqtbvsnuiefvpoda.supabase.co/* medium Backend Supabase instance; external data endpoint warrants scrutiny but fits SaaS model.
Pillar Scores
Permissions2.30
Reputation5.50
Network1.50
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality3.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:26
Listing SHA
d6974e7c813c…
Force block
— not fired
Score recovered
no
Elapsed
—