OutRun Offline Game
mbmoepkknemagccpieajeildcmlfepkh
Risk Score
5.39
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Install and uninstall URL hijack both present — extension opens 3rd-party URLs on install/uninstall.
- Brand impersonation: mentions 'Google' without ownership; developer is anonymous hotmail address.
- Extension not updated in 31 months — zombie extension ripe for acquisition or silent compromise.
- Free-webmail developer (hotmail) with no developer name — low accountability, high takeover risk.
- External JS hosts (s3-us-west-2.amazonaws.com, www.w3technic.com) with no CSP to constrain them.
Evidence
- install_url_hijack + uninstall_url_hijack crx Both install and uninstall URL hijacks flagged; targets null but pattern matches monetization shell.
- brand_impersonation store brand_mention.is_impersonation=true; mentions 'google' without confirmed ownership; dev is hotmail.
- anonymous_developer store developer_name is empty; developer_email is mcdadeheadeu@hotmail.com — free webmail, no business identity.
- stale_extension store Last updated November 2023; 31 months since update — high acquisition/compromise risk.
- no_csp crx content_security_policy is null (MV3 default strict, but external hosts in js_external_hosts flagged).
- external_js_hosts crx Contacts s3-us-west-2.amazonaws.com and www.w3technic.com — 2 distinct external domains.
- verified_publisher_with_stale_and_hotmail store verified_publisher=true but 0c cap applies: months_since_update=31 >18; discount capped at -1.0.
- privacy_policy_retention_missing api Policy fetched, scoped, data_collection=true, but retention=false and third_party_silence=true.
Pillar Scores
Permissions0.00
Reputation7.50
Network2.00
Webstore8.00
Maintenance8.50
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
db9285ce805d…
Force block
— not fired
Score recovered
no
Elapsed
33.6s