Slot Ramses
gbhhgipmedccnankkjchgcidiigmioio
Risk Score
3.74
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Uninstall URL hijack and install URL hijack detected — monetization/tracking redirect pattern.
- Privacy policy hosted on third-party CDN (cdn.cloudapi.stream), not scoped to this extension; no data collection scope stated.
- jquery@3.2.1 bundles 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023), unfixed.
- Sandbox CSP allows unsafe-inline and unsafe-eval, enabling script injection risk in sandboxed context.
- Gmail developer with no verified publisher; 11 external JS hosts referenced in extension bundle.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() called; install_url_hijack also true, onInstalled opens popup/index.html.
- privacy_policy_not_scoped crx Policy at cdn.cloudapi.stream: scope_extension=false, data_collection=false, third_party_sharing=true.
- cve_moderate_jquery crx jquery@3.2.1 has 3 moderate CVEs; fixed_in 3.5.0; version still bundled unfixed.
- sandbox_csp_unsafe manifest Sandbox CSP includes unsafe-inline and unsafe-eval on script-src within sandboxed page.
- free_webmail_dev store Developer email kiev3381917@gmail.com — free webmail, no verified publisher, no business website.
- external_js_hosts crx 11 external JS hosts referenced: bnjmnt4n.now.sh, cloudapi.stream, codecanyon.net, createjs.com, etc.
- low_install_count store Only 22 installs; tail-attack-surface risk low but extension has minimal trust signal.
- install_url_hijack_target crx install_url_target is popup/index.html (internal); uninstall target null — hijack flag raised but low impact.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Pillar Scores
Permissions0.00
Reputation6.50
Network0.00
Webstore6.00
Maintenance1.50
Privacy9.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:58
Listing SHA
20d78acfd02b…
Force block
— not fired
Score recovered
no
Elapsed
—