Web Client for game Cricket Batter Challenge
dcamdpfclondppklabgkfaofjccpioil
Risk Score
4.48
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but admits third-party sharing without scoping to this extension — score +10.0.
- Free-webmail Gmail developer with no verified business; numbered-alias pattern (kiev3381917) elevates rep risk.
- function_constructor (new Function()) found in 3 JS files — dynamic code execution risk without CSP.
- No content_security_policy (MV3 default is strict, but absence of explicit CSP with function_constructor is concerning).
- Four distinct host_permissions including top.rodeo with no stated purpose; 3 countries of hosting increases geo-diversity surface.
Evidence
- free_webmail_developer store Developer email kiev3381917@gmail.com — numbered alias, no verified business domain.
- privacy_policy_third_party_sharing api Policy fetched but scope_extension=false, data_collection=false, third_party_sharing=true → +10.0 privacy.
- function_constructor crx new Function() in background.js, content-sidebar.js, newtab-app.js — dynamic code execution.
- no_csp manifest content_security_policy is null; MV3 default applies but explicit CSP absent alongside dynamic code patterns.
- unrelated_host_permission manifest https://top.rodeo/* has no stated game/API purpose; raises suspicious outbound surface.
- geo_diversity api JS hosts span CA, NL, US — 3 countries, below +1.5 threshold of 4.
- low_install_count store Only 273 installs; limited blast radius but opaque developer identity.
- manifest_name_localized manifest manifest_name and description use __MSG__ placeholders — description unverifiable from manifest directly.
Permissions Breakdown
- storage low Local data persistence; low standalone risk.
- sidePanel low UI surface for side panel; no data access.
- https://www.googleapis.com/* medium Access to Google APIs; could be used to act on user's Google account data.
- https://wheel.cloudapi.stream/* medium Developer-controlled CDN domain; opaque data flows possible.
- https://mines.cloudapi.stream/* medium Second developer-controlled subdomain; widens outbound surface.
- https://top.rodeo/* medium Unrelated third-party domain with no stated purpose; suspicious.
Pillar Scores
Permissions2.00
Reputation7.50
Network3.50
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:54
Listing SHA
b7ed0d01a822…
Force block
— not fired
Score recovered
no
Elapsed
—