Classic Dungeon Game
jididilbbeilbgdfoflncbphhbcklmca
Risk Score
5.95
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: mentions 'google' in metadata but confirmed_owner=false, free-webmail dev with no business identity
- Install and uninstall URL hijack flags set — extension opens/redirects on install and removal
- Privacy policy fetch failed (HTTPError) and points to flappybird.ee — unrelated domain, unverifiable
- Stale 31 months; combined with MV2-era shell pattern and is_shell_pattern=true raises zombie-game concern
- Game-portal shell pattern detected (description_promise.is_shell_pattern=true) with install/uninstall hijack
Evidence
- brand_impersonation store brand_mention lists 'google', confirmed_owner=false, is_impersonation=true; dev email mcdadeheadeu@hotmail.com
- install_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; both targets null — traffic redirection on lifecycle events
- shell_pattern store description_promise.is_shell_pattern=true; game wrapper with install/uninstall hooks matches game-portal shell
- privacy_policy_unreachable api privacy_policy_classification.fetched=false (HTTPError); URL points to flappybird.ee, unrelated to extension
- stale_extension store months_since_update=31; no updates in over 2.5 years for a 30k-install game extension
- free_webmail_dev_no_name store developer_name empty, developer_email=hotmail.com; no business identity verifiable
- no_csp crx content_security_policy=null; MV3 provides default but js_external_hosts present: image.ibb.co, www.w3technic.com
- operator_cluster_dev_email_siblings api sibling_counts_by_dim.dev_email=2 indicating same hotmail address used across multiple extensions
Pillar Scores
Permissions0.00
Reputation8.00
Network2.00
Webstore9.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA
6cc6df4274e0…
Force block
— not fired
Score recovered
no
Elapsed
18.4s