3D Soccer Slot Machine
kknakidneabpfgepadgpkibalcnabnnh
Risk Score
3.67
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Uninstall URL hijack flagged despite null target — suspicious lifecycle interception attempt.
- Install URL hijack redirects to popup/index.html on install — unusual install-time navigation.
- Privacy policy hosted on CDN (cloudapi.stream), not scoped to this extension, admits third-party sharing.
- Free-webmail developer (gmail.com), no developer name listed, no verified business identity.
- 11 external JS hosts referenced including goo.gl shortlinks and anonymous/personal domains.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() called; target is null but flag is true — lifecycle hijack attempt.
- install_url_hijack crx onInstalled opens popup/index.html; coded as install URL hijack in scan.
- free_webmail_dev_no_name store Developer email nadejdinv@gmail.com; developer_name is empty; no business website.
- privacy_policy_not_scoped api Policy fetched from CDN cdn.cloudapi.stream; scope_extension=false, third_party_sharing=true.
- sandbox_csp_unsafe_eval manifest Sandbox CSP includes unsafe-inline and unsafe-eval on script-src; risky for sandboxed pages.
- external_js_hosts crx 11 external hosts in JS: bnjmnt4n.now.sh, goo.gl, codecanyon.net, harrytheo.com, cloudapi.stream etc.
- verified_publisher store verified_publisher=true; provides mild reputation relief but gmail address limits discount.
- low_install_count store Only 238 installs; limited blast radius but low scrutiny.
Pillar Scores
Permissions0.00
Reputation6.50
Network0.00
Webstore8.00
Maintenance1.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 14:18
Listing SHA
3f5cd7ccda70…
Force block
— not fired
Score recovered
no
Elapsed
—