Game SkySpeedster
cbnekafldflkmngbgmbnfmchjaelnhem
Risk Score
3.74
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Free-webmail dev (gmail) with no developer name — unverifiable identity, reputation floor 7.5.
- Uninstall URL hijack flag set — extension registers an uninstall callback to a third-party target.
- Install URL hijack flag set — onInstalled opens popup/index.html (internal, but hijack pattern detected).
- Privacy policy hosted on CDN (cdn.cloudapi.stream), scope_extension=false, admits third-party sharing — generic policy +9.0.
- DOM-XSS sink: innerHTML assigned from navigator.userAgent in popup/scripts/supportcheck.js.
Evidence
- free_webmail_dev_no_name store Developer email viktornadiezhdin@gmail.com; developer_name is empty. Reputation floor applied at 7.5.
- uninstall_url_hijack crx uninstall_url_hijack=true; target=null. Webstore +3.0 applied per rubric.
- install_url_hijack crx install_url_hijack=true; target=popup/index.html (internal). Webstore +2.0 applied.
- privacy_policy_generic_cdn api Policy on cdn.cloudapi.stream; scope_extension=false, data_collection=false, third_party_sharing=true → +9.0.
- dom_sink_innerhtml crx dom_sink_innerhtml_userctrl in popup/scripts/supportcheck.js; csp_present=true, no eval finding → +0.5.
- sandbox_unsafe_eval manifest CSP sandbox page allows unsafe-inline and unsafe-eval; extension_pages CSP is strict (self only).
- maintenance_6_12mo store months_since_update=11; falls in 6-12mo band → +3.5.
- verified_publisher store verified_publisher=true; -3.0 to reputation but floor enforced at 7.5 due to free-webmail+no-name.
Pillar Scores
Permissions0.00
Reputation7.50
Network0.00
Webstore6.00
Maintenance3.50
Privacy9.00
Code Quality0.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:28
Listing SHA
79096bd315a8…
Force block
— not fired
Score recovered
no
Elapsed
—