Pirat Slot
kbnkkecifeppobnemkielnpagifkobki
Risk Score
5.12
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- <all_urls> host permission grants read/write to every page visited; severely over-permissioned for a slot game.
- Privacy policy hosted on cdn.cloudapi.stream not scoped to this extension; admits third-party sharing without context.
- free-webmail dev (gmail) with no developer name raises accountability gap.
- new Function() constructor in 3 JS files enables dynamic code execution risks.
- MV3 + no CSP means no additional script-source restriction on extension pages.
Evidence
- host_permissions_all_urls manifest <all_urls> declared alongside sidePanel for a slot-game extension; no content_scripts to justify breadth.
- free_webmail_dev_no_name store developer_email=viktornadiezhdin@gmail.com, developer_name empty; no verifiable business identity.
- privacy_policy_unscoped_third_party api Policy fetched; scope_extension=false, data_collection=false, third_party_sharing=true — admits 3P sharing without scope.
- function_constructor_multiple_files crx new Function() found in background.js, content-sidebar.js, newtab-app.js — dynamic code execution risk.
- csp_absent manifest content_security_policy is null; MV3 default applies but no explicit restriction on extension pages.
- third_party_host_permission manifest https://top.rodeo/* host permission; unknown third-party gambling/ad domain, purpose undisclosed.
- verified_publisher store verified_publisher=true; partial trust credit, but free-webmail and no dev name limit confidence.
- install_count_missing store No install count available; blast radius unknown, tail_attack_surface possible.
Permissions Breakdown
- storage low Local key-value storage only; no cross-origin data exposure.
- sidePanel low Renders UI in side panel; no elevated data access.
- <all_urls> (host) high Full read/write access to every page the user visits; broad attack surface.
- https://top.rodeo/* (host) medium Specific third-party domain access; purpose unclear for a slot-game extension.
Pillar Scores
Permissions5.50
Reputation6.50
Network4.00
Webstore3.00
Maintenance3.50
Privacy9.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:01
Listing SHA
14f6dd58d213…
Force block
— not fired
Score recovered
no
Elapsed
—