Draw on Web
kbjgcbphgpmocnifmiabfcnglomheonp
Risk Score
3.52
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Uninstall and install URL hijacks route user events to cloudapi.stream — a third-party domain unrelated to the stated tool.
- Privacy policy admits third-party data sharing but lacks retention disclosure; hosted on CDN subdomain, not dev-controlled domain.
- Free-webmail developer (gmail) with no developer name listed reduces accountability.
- Privacy policy scope is extension-specific but omits retention, and third_party_sharing == true raises data-handling concern.
- Install redirects to cloudapi.stream on every install event; monetization or tracking signal even with no bad-host hit.
Evidence
- install_url_hijack manifest onInstalled opens https://cloudapi.stream/install/?reason= — third-party domain, monetization/tracking shape.
- uninstall_url_hijack manifest chrome.runtime.setUninstallURL() set; target null but flag is true — exfil/redirect risk on uninstall.
- free_webmail_developer store Developer email is viktornadiezhdin@gmail.com; no developer name; no verified business domain.
- privacy_policy_third_party_sharing api Policy fetched, scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- privacy_policy_cdn_hosted store Privacy policy at cdn.cloudapi.stream — CDN subdomain, not a dev-controlled domain matching email.
- js_external_host crx Extension references cloudapi.stream as external JS host; no bad-host hit but unknown third-party CDN.
- verified_publisher store verified_publisher=true; partial trust discount applied per rubric.
- maintenance_stale store months_since_update=12; falls in 6-12mo band (+3.5).
Permissions Breakdown
- activeTab medium Access current tab on user action; limited scope but enables content injection.
- storage low Local data persistence; low standalone risk.
- scripting medium Can inject scripts into active tab; combined with activeTab enables full DOM access on click.
Pillar Scores
Permissions2.00
Reputation6.50
Network2.00
Webstore5.00
Maintenance3.50
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:56
Listing SHA
a57cc964712d…
Force block
— not fired
Score recovered
no
Elapsed
—