Idle Mining Empire
gapphnfanjgnihehlmcnigefojdhphff
Risk Score
5.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack + install URL hijack both present despite null targets — high suspicion of analytics/redirect pipeline.
- Privacy policy URL returns HTTP error (fetch_error); effectively no accessible privacy policy.
- Developer is free-webmail (gmail) with no developer name and no verified business domain.
- Extension is 20 months stale (High maintenance risk) on MV3.
- Manifest name/description use unexpanded i18n tokens suggesting shell/placeholder pattern.
Evidence
- uninstall_url_hijack crx uninstall_url_hijack=true with null target; install_url_hijack=true with null target — monetization/tracking pipeline suspected.
- privacy_policy_fetch_error store Privacy policy at play.owhit.com/page/privacy returns HTTPError; treated as no accessible policy.
- free_webmail_no_dev_name store Developer email yakupogluokul@gmail.com; developer_name empty; no business domain identity.
- stale_extension store Last updated January 7, 2025; 20 months since update triggers High maintenance score.
- manifest_i18n_shell manifest manifest_name='__MSG_appName__' and manifest_description='__MSG_appDesc__' — unexpanded i18n tokens, possible placeholder shell.
- js_external_host crx External JS host play.owhit.com present; same domain as inaccessible privacy policy.
- verified_publisher store verified_publisher=true but discounts capped due to stale >18mo (v3.5 invariant 0c/E).
- low_install_count store Only 159 installs; no ratings. Minimal blast radius but tail-attack-surface pattern.
Pillar Scores
Permissions0.00
Reputation7.50
Network0.00
Webstore7.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 13:51
Listing SHA
1a1eeb9da7fd…
Force block
— not fired
Score recovered
no
Elapsed
—