Best Blackjack
caiefmpbohoambhdmbgkejacmipnkomb
Risk Score
5.47
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection + third-party sharing but is NOT scoped to this extension (hosted on operator CDN, not dev domain).
- Uninstall URL hijack flagged AND install URL hijack flagged — classic monetization-shell behavior.
- Free-webmail developer (gmail), no developer name, no verified business domain.
- Host permissions span 3 opaque third-party domains (cloudapi.stream ×2, top.rodeo) alongside googleapis.
- Sandbox CSP allows unsafe-inline + unsafe-eval; manifest name/description are placeholder MSG strings.
Evidence
- uninstall_url_hijack + install_url_hijack crx Both install and uninstall URL hijacks flagged; strong monetization-shell indicator (+3.0+2.0 Webstore).
- privacy_policy_classification api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (D rule).
- developer_identity store Free-webmail gmail dev, no developer_name, verified_publisher=true but email is gmail.
- host_permissions_opaque manifest wheel.cloudapi.stream, mines.cloudapi.stream, top.rodeo are non-Google third-party gambling endpoints.
- sandbox_csp_unsafe crx Sandbox CSP contains unsafe-inline and unsafe-eval on script-src.
- manifest_placeholder_strings crx manifest_name and manifest_description are __MSG_name__/__MSG_desc__ — obfuscates true function from store review.
- js_external_hosts crx 8 external JS hosts including goo.gl shortener and www.harrytheo.com; 3 countries (CA, NL, US).
- low_install_count store Only 217 installs; tail-attack-surface not flagged by tool but combined with hijacks is suspicious.
Permissions Breakdown
- identity low OAuth identity; low risk alone, but paired with googleapis host perm enables account data access.
- https://www.googleapis.com/* medium Broad Google API access; combined with identity permission could read account data.
- https://wheel.cloudapi.stream/* medium Non-Google third-party host on same CDN serving the privacy policy; unverifiable operator.
- https://mines.cloudapi.stream/* medium Second cloudapi.stream subdomain; same unverifiable operator cluster.
- https://top.rodeo/* medium Gambling-adjacent TLD with unknown operator; opaque data destination.
Pillar Scores
Permissions3.00
Reputation7.00
Network2.50
Webstore8.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:59
Listing SHA
985a7a1a45b4…
Force block
— not fired
Score recovered
no
Elapsed
—