Christmas Eve - Slot Machine
ibelidmkbnjmmpjgfibbdbkamgcbnjdm
Risk Score
4.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy hosted on cdn.cloudapi.stream admits data collection and third-party sharing but is not scoped to this extension — triggers D rule (+10.0 privacy).
- No developer name listed; .rodeo TLD with CDN-hosted policy from a different domain raises accountability concerns.
- 12 distinct external JS hosts referenced in bundle; includes topup.cloudapi.stream suggesting in-app purchase / monetization surface.
- Sandbox CSP allows unsafe-inline and unsafe-eval, weakening sandboxed page isolation.
- Very low install count (26) with no ratings and no developer identity — minimal accountability if extension behavior changes.
Evidence
- privacy_policy_generic_admits_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
- no_developer_name store developer_name is empty; reputation start 5.0 +1.0 for missing dev name.
- developer_email_tld store support@top.rodeo uses .rodeo TLD; no verified business; +1.0 elevated-risk TLD.
- sandbox_csp_unsafe manifest Sandbox directive includes unsafe-inline and unsafe-eval on script-src.
- external_hosts_count crx 12 distinct registrable-domain external hosts including topup.cloudapi.stream and mines.cloudapi.stream.
- host_permissions_dev_domains manifest 3 host_permissions point to developer-controlled cloudapi.stream subdomains and top.rodeo.
- maintenance_3_6_months store months_since_update=10; falls in 6-12mo band → +3.5 maintenance.
- code_findings_clean crx code_findings_raw empty, obfuscation_score=0.0 → code quality pillar 0.0.
Permissions Breakdown
- identity low OAuth token access; low scope with no declared OAuth scopes in manifest.
- host:https://www.googleapis.com/* low Google APIs access, consistent with identity permission.
- host:https://wheel.cloudapi.stream/* medium Developer-controlled CDN subdomain; not a recognized third-party service.
- host:https://mines.cloudapi.stream/* medium Developer-controlled CDN subdomain; game backend with unknown data handling.
- host:https://top.rodeo/* medium Developer's own domain; unclear what data is sent there.
Pillar Scores
Permissions1.50
Reputation6.50
Network3.50
Webstore3.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:43
Listing SHA
94d110758e57…
Force block
— not fired
Score recovered
no
Elapsed
—