Traffic Escape Game
eejjlbledknodmhedabibmagbofnonal
Risk Score
2.47
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Uninstall URL hijack and install URL hijack flags active — potential traffic redirection on install/uninstall.
- Privacy policy hosted on CDN (cloudapi.stream), not scoped to this extension, data_collection=true with third_party_silence.
- Free-webmail developer (gmail) with no developer name listed raises accountability concerns.
- DOM-XSS sink via innerHTML with navigator.userAgent in popup script.
- Privacy policy admits data collection but lacks retention disclosure and third-party sharing clarity.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() called; target null but flag is true — traffic redirection risk on uninstall.
- install_url_hijack crx onInstalled opens popup/index.html — internal target, low severity but flag present.
- free_webmail_developer store Developer email viktornadiezhdin@gmail.com; no developer name, no business domain.
- privacy_policy_not_scoped api Policy at cdn.cloudapi.stream: scope_extension=false, data_collection=true, retention=false, third_party_silence=true.
- dom_xss_sink crx innerHTML set from navigator.userAgent string in popup/scripts/supportcheck.js — DOM-XSS vector.
- sandbox_csp_unsafe_eval manifest Sandbox CSP allows unsafe-inline and unsafe-eval on script-src; extension_pages CSP is strict.
- verified_publisher store Verified publisher badge present; partial trust credit applied.
- low_installs store Only 153 installs; limited blast radius but tail-attack-surface anomaly not triggered per computed data.
Pillar Scores
Permissions0.00
Reputation6.50
Network0.00
Webstore6.50
Maintenance1.50
Privacy9.00
Code Quality0.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:58
Listing SHA
ba714c507752…
Force block
— not fired
Score recovered
no
Elapsed
—