Mini Golf World
kblomapfkjidbbbdllmofkcakcenkmec
Risk Score
3.22
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy not scoped to this extension and hosted on dev CDN; third-party sharing admitted without extension scope.
- Uninstall URL hijack flag set — attempts to capture uninstall events for redirect.
- Three medium-severity jQuery CVEs (3.2.1) bundled; fixed version is 3.5.0.
- Developer uses free Gmail with no verified publisher status; throwaway-pattern email.
- Sandbox CSP permits unsafe-eval and unsafe-inline, weakening XSS mitigations for sandboxed pages.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() called; uninstall_url_hijack=true per scan.
- install_url_hijack crx install_url_hijack=true, opens popup/index.html on install (internal target, lower severity).
- jquery_cve_bundle crx jquery@3.2.1 bundled with 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed in 3.5.0.
- privacy_policy_inadequate store Policy fetched from CDN; scope_extension=false, data_collection=false but third_party_sharing=true.
- sandbox_csp_unsafe crx Sandbox CSP allows unsafe-eval and unsafe-inline on script-src, weakening sandboxed page security.
- free_webmail_developer store Developer email kiev3381917@gmail.com; no verified publisher; no business domain.
- js_external_hosts crx 10 external JS hosts referenced incl. bnjmnt4n.now.sh, goo.gl, harrytheo.com — broad external surface.
- host_geo_diversity crx JS hosted across 3 countries (CA, NL, US); country_count=3, below +1.5 threshold of 4.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- host: https://www.googleapis.com/* medium Access to Google APIs; moderate risk depending on use.
- host: https://wheel.cloudapi.stream/* medium Access to developer-controlled CDN domain; data exfil possible.
- host: https://mines.cloudapi.stream/* medium Second developer-controlled CDN endpoint; same exfil concern.
Pillar Scores
Permissions2.00
Reputation6.50
Network2.00
Webstore5.00
Maintenance1.50
Privacy9.00
Code Quality0.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:57
Listing SHA
cf42841ccc7f…
Force block
— not fired
Score recovered
no
Elapsed
—